Access & authentication
- Accounts are protected by email/password or Google sign-in; there are no anonymous accounts.
- Every workspace record is scoped to its owner through database row-level security policies.
- Administrative capabilities are granted through a separate roles table, never stored on the user profile.
- Privileged operations run server-side only, after the caller's identity has been verified.
Your data & your knowledge base
- Knowledge you upload is used to answer on behalf of your own agents only.
- We do not sell your data, and we do not share it with other customers.
- You can delete your account and its associated records from your account settings at any time.
- Data is transmitted over TLS and stored in a managed Postgres database with access controls in place.
AI providers & subprocessors
- Agent replies are generated through our AI gateway; prompts and conversation context are sent to the model provider to produce a response.
- Payments are processed by PayPal. We never see or store your card details.
- Analytics is Google Analytics 4 with Consent Mode v2 — measurement stays cookieless until you accept analytics cookies.
- Ask support@wakeeli.net for the current subprocessor list before signing a data-processing agreement.
Reliability
- Agent health is measured from real request outcomes, not estimates. Where a live reliability panel is shown, it reflects recorded checks over the stated window.
- We publish the timestamp of the last successful check so you can judge how fresh the numbers are.
- We do not publish an uptime figure for a service we are not actually measuring.
What we do not claim
- Wakeeli is not currently certified under SOC 2, ISO 27001, HIPAA or PCI DSS.
- We do not publish customer counts, ratings or testimonials that we cannot evidence.
- If you need a specific compliance commitment, contact us and we will tell you plainly whether we can meet it today.
Report a security issue
If you find a vulnerability, email support@wakeeli.net with reproduction steps. We prioritise security reports over other mail, and we will not pursue good-faith research that does not access other users' data.