Security

Built so your compliance officer can say yes.

A summary of the controls in the product today. Our full security review is available to insurers in due diligence. A data processing agreement is signed before any real policyholder data is sent to Polisync.

POPIA

Consent before contact
Every policyholder has a consent status: opted in, opted out or unknown. Only opted-in policyholders are messaged, and unknown is the default. An opt-in needs a source and a timestamp, and an older opt-in can never override a newer opt-out.
STOP means stop
Replying STOP, unsubscribe or opt out on WhatsApp opts the policyholder out immediately and cancels anything scheduled for them. Consent is checked again at the moment of sending, so a message already queued is cancelled too.
Data minimisation
Polisync keeps the policyholder’s name and WhatsApp number, policy and contact references, product, premium, debit day and renewal date. Payloads carrying ID numbers, bank or card details, addresses or dates of birth are rejected outright, and only the offending key is logged, never the value.
Retention
A scheduled purge runs every night. Contacts are deleted 24 months after the last event about them, events after 24 months, and WhatsApp messages and conversations after 12 months.
Manual changes are accountable
Changing a policyholder’s consent from the dashboard needs a reason, and the change is recorded against the person who made it.

Audit and integrity

An append-only audit log
Every write is audited: ingest, consent changes, every gate decision, deliveries, Actions, webhooks, templates, playbooks and API keys. The log cannot be edited. The application refuses updates, and on Postgres a database trigger rejects any UPDATE to the table. Rows leave only through the retention purge.
Why a message was or was not sent
Each of the six gates writes its decision to the audit log against the event, so the answer to “why did this policyholder not get a message?” is on the event page.

Isolation and access

Tenant isolation that fails closed
Every tenant-owned record is filtered by tenant at the database query level. If no tenant context is present, queries return nothing rather than everything. Another tenant’s records return “not found”, on the dashboard and through the API.
Keys and secrets
API keys are stored as a hash and shown once. WhatsApp access tokens and webhook signing secrets are encrypted at rest and never shown back in the dashboard.
Error reporting is scrubbed
Phone numbers, names, message content, tokens and signatures are removed before anything reaches error monitoring.

Messages and webhooks

Meta-approved templates only
Outbound messages are templates approved by Meta for your WhatsApp Business Account. An approval for one account does not carry over to another.
Signed webhooks
Webhooks to your system carry an HMAC-SHA256 signature over a timestamp and the body, so you can reject forgeries and replays.
SSRF guard
Webhook targets must be public HTTPS addresses. Loopback, private, link-local and cloud metadata ranges are refused. The address is resolved and checked at save time and again on every send, and the connection is pinned to the address that was checked.

Doing due diligence?

Ask for the security review and a draft data processing agreement. We will walk your team through both.

Request a demo