Security

The technical and organisational measures protecting data in MapleChat.

Effective 2026-09-30

This page describes the measures we take to protect data in MapleChat. We describe what we actually do; where something is planned rather than in place, we say so.

Tenant isolation

MapleChat is multi-tenant: many businesses share the same infrastructure. Separation between them is enforced in the database itself, not only in application code. Every tenant-scoped table carries the owning company, and queries are filtered against the authenticated company on every request. A query that omits the filter returns nothing rather than another tenant's rows.

This matters because application-level checks fail open when a developer forgets one. Enforcing isolation at the data layer means the default outcome of a mistake is no data, not the wrong data.

Authentication and access

Team members authenticate through Firebase Authentication. Sessions are carried by short-lived signed tokens that encode the user's company, role and team assignments; the server re-validates them on every request and never trusts a client-supplied company identifier.

Access within a workspace is governed by roles — Owner, Admin, Supervisor, Operator and Viewer — which determine what each person can see and do. Permission decisions are made on the server; hiding a control in the interface is never the only thing preventing an action.

Encryption

Traffic is encrypted in transit with TLS. The MapleChat domain is on the HSTS preload list at the top-level-domain level, so browsers will not connect to it over plain HTTP under any circumstance. TLS terminates at Cloudflare's network, which carries traffic on to our servers over an encrypted tunnel; Cloudflare is listed on the Subprocessors page.

The credentials that connect your WhatsApp Business Account are encrypted by MapleChat before they are written to the database, and the keys that decrypt them are kept separately from it.

Credentials and secrets

Access credentials for your WhatsApp Business Account, and all service secrets, are supplied through environment configuration and validated at start-up. They are not committed to source control and are not written to application logs.

Logging and monitoring

We keep structured application logs and traces to operate and debug the service. Logs are written to exclude message content and authentication tokens. They are retained for a limited operational period and then discarded.

Backups

The database is backed up on a regular schedule and backups are retained for a defined window. Deleted data is removed from backups within 30 days, as described in Data Deletion.

Development practices

Changes are reviewed before release and covered by an automated test suite, including tests that specifically assert tenant isolation holds. Dependencies are kept current.

What we do not yet claim

We hold no third-party security certification at this time — no SOC 2 report and no ISO 27001 certificate — and we have not completed an independent penetration test. We do not claim disk-level encryption at rest across the infrastructure we run: the WhatsApp credentials described above are encrypted by MapleChat itself, but the database and stored media otherwise rely on whatever the underlying hosting provides. We would rather say so plainly than imply assurance we do not have. This page will be updated when that changes.

Reporting a vulnerability

If you believe you have found a security problem, write to security@maplechat.app with enough detail to reproduce it. We will acknowledge within 5 business days and keep you updated. Please give us a reasonable opportunity to fix the issue before disclosing it publicly. We will not pursue legal action against researchers who act in good faith, avoid privacy violations and do not degrade the service.