Media

Money

Dispatch

Company

Security

Security at WAVE

We build on a hardened, compliance-aligned stack and welcome responsible disclosure.

/.well-known/security.txt · RFC 9116Open the file
$ curl -s https://wave.online/.well-known/security.txtContact: mailto:security@wave.online
Expires: 2027-01-01T00:00:00Z
Preferred-Languages: en
Canonical: https://wave.online/.well-known/security.txt
Policy: https://wave.online/security
Acknowledgments: https://wave.online/security#acknowledgments
01

Our posture

4 areas Each area, what WAVE does, and the linked document where one is published.
AreaWhat we doEvidence
Compliance postureGDPR/CCPA aligned, HIPAA-ready under a signed BAA, EU AI Act Article 26 record-keeping, with a signed DPA available.DPABAAEU AI Act
Defense in depthEvery request is authenticated, scoped, and metered at one edge gateway, across every product and agent.
EncryptionTLS in transit and at rest across the platform. Secrets are centrally managed and never committed to source.
AuditabilityImmutable audit records with multi-year retention, carried end to end through the gateway.

Who we build on: the subprocessor roster in the Trust Center.

02

Responsible disclosure