Skip to content
Bzzip
Start free
Security

Who can read a conversation.

Your customers are trusting you with their messages; you are trusting us. Here is exactly how that trust is handled — in plain words, not badges.

Encryption at rest

Channel credentials — the keys Meta issues when you connect a number — and any AI key you bring are encrypted at rest, with rotating keys. Backups are encrypted in transit and at rest.

Workspace isolation

Each workspace is a security boundary. Conversations, knowledge and credentials belong to one workspace; a member of one can never read another's, even inside the same account.

What Meta sees

WhatsApp messages travel through the WhatsApp Business Platform, operated by Meta, under Meta's terms. Bzzip sends Meta nothing beyond what delivering your messages requires — no analytics, no extra profile data.

Data residency

Production data is stored in one region and does not move casually. Brazilian accounts are handled under the LGPD, EU accounts under the GDPR; exports and deletion are yours to ask for at any time.

Who can read a conversation

The members of that workspace. Not other workspaces, not other customers, and not Bzzip staff in the ordinary course — support access requires your consent and is logged.

Your AI key

A bring-your-own key is used only to generate replies inside your workspace, is never shown again after you save it, and can be revoked on your provider's side at any moment. We do not train on your conversations.

Something we have not answered? Ask us directly — security questions get a person, not a form letter.