Secure by default.
HMAC-signed webhooks, 21-scope keys, compliance logging, and automatic key scanning: the boring parts, done properly.
Compliance built in.
HMAC-signed webhooks, role-scoped keys, and a full audit trail are on from the first request. GDPR and LGPD aren't checkboxes: residency, purge guarantees, and processor agreements are part of the product.
Data lives where it should.
One rule, applied per data class: your data lives in the nearest jurisdiction (Brazil, India, or Switzerland), while the console account, configuration, and secrets stay central in Switzerland.
The console account, configuration, settings, and secrets. Stored in Switzerland under Softium LLC, for every user.
Brazilian users' chats, media, and contacts are stored on Brazilian infrastructure, LGPD-native.
Account and auth data live in the nearest jurisdiction: India stays in India, Brazil in Brazil, everyone else in Switzerland.
Keys that can't do more than they should.
21 scopes per key, checked before anything executes, and every sensitive action lands in an exportable audit trail. Leaked keys revoke themselves.
Boring, audited, on by default.
Every webhook is HMAC-signed, every key is scoped, every admin action lands in a 365-day log. There is nothing to enable.
GDPR and LGPD aren't checkboxes: data residency, purge guarantees, and processor agreements are part of the product, hosted in Switzerland.
- 21
- key scopes
- 365 days
- audit retention
- 2
- regimes: GDPR · LGPD
A request's paper trail.
Every call leaves the same three marks.
The security posture.
The boring parts, done properly.
Ship a WhatsApp integration this afternoon.
Free on the sandbox. No credit card. The projects you start here migrate straight into production.