Security
Security at WAVE
We build on a hardened, compliance-aligned stack and welcome responsible disclosure.
$ curl -s https://wave.online/.well-known/security.txtContact: mailto:security@wave.online Expires: 2027-01-01T00:00:00Z Preferred-Languages: en Canonical: https://wave.online/.well-known/security.txt Policy: https://wave.online/security Acknowledgments: https://wave.online/security#acknowledgments
Our posture
| Area | What we do | Evidence |
|---|---|---|
| Compliance posture | GDPR/CCPA aligned, HIPAA-ready under a signed BAA, EU AI Act Article 26 record-keeping, with a signed DPA available. | DPABAAEU AI Act |
| Defense in depth | Every request is authenticated, scoped, and metered at one edge gateway, across every product and agent. | |
| Encryption | TLS in transit and at rest across the platform. Secrets are centrally managed and never committed to source. | |
| Auditability | Immutable audit records with multi-year retention, carried end to end through the gateway. |
Who we build on: the subprocessor roster in the Trust Center.
Responsible disclosure
Found a vulnerability? Email security@wave.online with details and reproduction steps. We acknowledge reports promptly, do not pursue legal action for good-faith research, and will credit you once a fix ships.
The same policy is published machine-readable at /.well-known/security.txt (RFC 9116).