Security and data handling

Each business's data is kept separate, WhatsApp credentials are encrypted, and your team can erase customer data on request. Here is what Bridge does today.

Separation between businesses

  • Row-level security isolates every business's data in the database.
  • Every data access is scoped to one workspace.
  • The app's database account has no superuser rights.

Your WhatsApp credentials

  • Stored encrypted with AES-256-GCM and bound to your workspace.
  • Never shown in the interface.

Incoming messages

  • Every message from Meta is checked against its signature, and anything that fails is rejected.
  • Duplicate deliveries are ignored.

Access

  • Passwords are hashed with bcrypt.
  • Workspace roles are Admin and Member. Only admins can change the WhatsApp connection, the bot's messages, saved replies and the share link.

In transit

  • Encrypted with TLS, with HSTS enforced.
  • A Content-Security-Policy limits which scripts the app loads.

Collecting less, deleting on request

  • The bot collects only the service, the timing and a name.
  • There are no clinical records or file uploads.
  • Messages in chats you close as junk or wrong number are deleted after 14 days.
  • Staff can permanently erase a conversation or a contact.

Questions about how Bridge handles data?

Book a demo
Book a demo Try the demo
Scroll to Top