Security: what is implemented, and what we do not claim
Security pages are usually written to reassure. This one is written to be checkable. Below is what is implemented, described specifically, followed by a plain list of what we do not hold, because a reviewer who finds one overstated claim will not believe the rest.
- HTTPS everywhere, with HSTS and a locked-down content security policy
- Per-workspace data separation, with a dedicated database on higher tiers
- Connection credentials encrypted at rest with AES-256-GCM
- An explicit statement of the certifications we do not hold
Short answer
Your conversations live in a workspace that is separated from every other customer’s, reachable only over HTTPS, behind role-based access, with connection credentials encrypted at rest. You can export your data and close the workspace yourself.
We hold no security certification. If a certification is a procurement requirement for you, we are not a fit yet, and we would rather you learn that here than three weeks into an evaluation.
The controls, specifically
Each row is a control that exists in the product today.
| Area | What is implemented |
|---|---|
| Transport | HTTPS throughout, with HSTS set to two years including subdomains, a content security policy scoped to the sources the app actually loads, X-Frame-Options DENY, MIME sniffing disabled, a strict referrer policy, and camera, microphone and geolocation disabled by policy |
| Workspace separation | A control database holds identity and routing; each workspace’s conversation data lives in its own tenant database. Trial and Starter workspaces run on shared infrastructure; Growth and Enterprise workspaces default to an isolated deployment |
| Credentials at rest | Tenant database connection secrets are encrypted with AES-256-GCM rather than stored in plain text |
| Sessions | Opaque server-side session tokens in a host-only cookie. Not a JWT sitting in browser local storage where any script can read it |
| Access control | Role-based, applied per workspace. Removing somebody is an account change; their conversations are reassigned and their history stays in the thread |
| Outbound requests | Any URL a customer supplies passes through a single SSRF guard before the platform will fetch it |
| Integrations | Every connector is a per-workspace entitlement that is off by default and switched on by our team, so no connection is made without a deliberate act |
| Getting out | Self-service export, subscription cancellation and workspace closure, plus an account deletion route |
| Reporting a problem | A published security.txt with a contact address and an expiry date |
What we do not hold, and do not claim
If any of these is a hard requirement, we are not the right vendor yet.
- ▲We are not SOC 2 certified. There is no report to send you.
- ▲We are not ISO 27001 certified.
- ▲We do not offer a HIPAA Business Associate Agreement, and WhatsApp should not be used for protected health information on our platform.
- ▲We publish no penetration test report or third-party audit, because none has been commissioned.
- ▲We do not promise anything about WhatsApp’s own end-to-end encryption. That is Meta’s architecture, described by Meta, and not something a software vendor can guarantee on Meta’s behalf.
- ▲We publish no uptime guarantee or SLA percentage on this page. The status page shows current state rather than a promise.
- ▲Trial and Starter workspaces share infrastructure with other customers. Logical separation is enforced, but if physical isolation is your requirement, that is a Growth or Enterprise deployment.
Where your data actually lives
Two kinds of database exist. A control database holds identity, workspace routing and the platform’s own bookkeeping. Each workspace’s conversations, contacts, notes and settings live in a tenant database belonging to that workspace.
Which infrastructure a tenant database sits on depends on the plan: trial and Starter default to shared, Growth and Enterprise default to isolated.
On a Coexistence connection, Meta synchronizes the most recent six months of chat messages and contacts that have a WhatsApp number into the platform, and excludes group chat messages. Anything older than that stays on the phone and never reaches us.
The part that is yours
Most WhatsApp data incidents are not platform breaches. They are an agent’s phone, a device left linked after somebody leaves, or a screenshot in a group chat.
On the app routes, access is tied to devices, so offboarding means unlinking a device on the primary phone. On a platform route, it means deactivating an account, which is both easier to do and easier to prove you did.
Decide what belongs on WhatsApp at all. Payment details, identity documents and clinical information are usually better handled somewhere designed for them, whatever channel the customer opened with.
Security questions
Are you SOC 2 or ISO 27001 certified?+
No, neither. We would rather tell you that on this page than after you have started an evaluation.
Is my workspace separated from other customers?+
Yes. Conversation data lives in a tenant database belonging to your workspace. Trial and Starter run on shared infrastructure; Growth and Enterprise default to an isolated deployment.
Are WhatsApp messages end-to-end encrypted?+
That is a property of WhatsApp’s platform, described by Meta, and not something we can promise on Meta’s behalf. What we can state is our side: HTTPS in transit, encrypted credentials at rest, and per-workspace separation.
How do I get my data out?+
Export it yourself from the billing area, then cancel or close the workspace. There is also an account deletion route.
How do I report a vulnerability?+
Use the contact in our published security.txt. Please report it before disclosing it publicly.
Sources, checked June 2026
Sources and documents
Controls above describe the product as implemented on the checked date. The legal documents govern; if this page and the DPA ever disagree, the DPA is what binds.
- marv.Inbox security.txt
- marv.Inbox privacy policy
- marv.Inbox data processing agreement
- Meta for Developers: Coexistence sync scope
Checked on 2026-08-03
Who wrote this
marv.Inbox team
Product and support team, marv.Inbox
We build marv.Inbox and we run our own customer conversations inside it, on the same WhatsApp number the buttons on this page open.
See whether this workflow fits your team
Explore the product, then request a walkthrough if you want help mapping channels, ownership, automation, or rollout.