Security & trust

Security, privacy and platform trust.

Convello handles some of your most sensitive conversations, so we treat security as a first-class product feature. We build on the official Meta and WhatsApp Business Platform APIs, encrypt your data end to end of our systems, and hold ourselves to the platform terms that keep your accounts in good standing.

How we protect your data

Security built into every layer

From encryption to access control to the way we ship code, our practices are designed to keep your customer conversations private and your business protected.

Encryption in transit & at rest

All traffic is protected with modern TLS 1.2+ and data is encrypted at rest with AES-256, so your conversations stay private on the wire and on disk.

Least-privilege access, SSO & RBAC

Granular role-based access control and single sign-on ensure teammates only reach what they need. Access is reviewed regularly and revoked promptly.

Audit logging

Sensitive actions are recorded in tamper-evident audit logs, giving your admins visibility into who did what and when across the workspace.

Reliable infrastructure

Hosted on hardened cloud infrastructure with a 99.9% uptime target, automated encrypted backups and disaster-recovery procedures we test regularly.

Secure development lifecycle

Code review, automated dependency scanning, and testing are built into every release, so security is checked continuously rather than bolted on.

Vendor & subprocessor management

We vet every subprocessor for security and privacy, keep an up-to-date list, and hold them to contractual data-protection commitments.

Platform compliance

Compliant with the Meta Platform Terms

Convello connects to your accounts exclusively through the official Meta Graph API and WhatsApp Business Platform — never scraping, never unofficial workarounds. Data we obtain through Meta's APIs is used solely to provide the service you signed up for.

Official APIs only

We use the official Meta Graph API and WhatsApp Business Platform — no unofficial access.

Used only to serve you

Data from Meta APIs is used solely to provide the service — never sold, never repurposed.

Platform Terms & policies

We adhere to the Meta Platform Terms and Developer Policies across everything we build.

Export & deletion

Request a full data export or deletion at any time — honored within 30 days.

Your data & privacy

You stay in control of your data

We collect only what's needed to run your workspace and give you the controls to manage it. Your customer conversations belong to you — we're the processor, not the owner.

  • Data residency in the United States — your workspace data is stored and processed in US-based infrastructure.
  • Retention controls — configure how long conversations and contact data are kept, and delete on demand.
  • Data Processing Agreement — a DPA is available on request for customers with contractual requirements.

Compliance posture. Our program is aligned with SOC 2 principles, with a SOC 2 Type II examination in progress. We're happy to share our current status and roadmap with prospective customers under NDA — just reach out to our team.

Data ownership. You can export your workspace data at any time and request deletion through our data deletion process. When you leave, your data leaves with you.

Responsible disclosure

Found a vulnerability? Tell us.

We welcome reports from security researchers and treat them as a priority. If you believe you've found a security issue in Convello, please email security@aleeconsult.com with the details and steps to reproduce. Please give us a reasonable window to investigate and remediate before any public disclosure — we'll keep you updated throughout and credit your work if you'd like.

Security questions? Let's talk.

Our team is happy to walk through our controls, share documentation, and answer anything your reviewers need.