Trust

Trust & compliance

How WAVE protects data, who we build on, and where to find every legal commitment.

Our posture

Privacy by design

GDPR & CCPA aligned, with a signed DPA available for customers. Consent-first analytics; Do-Not-Track respected.

Healthcare-ready

HIPAA-ready under a signed Business Associate Agreement (BAA).

AI transparency

EU AI Act Article 26 record-keeping, with immutable audit records and multi-year retention.

Messaging compliance

A2P 10DLC compliant messaging across the platform.

Encryption

TLS in transit and at rest; secrets centrally managed, never committed to source.

Gateway-enforced access

Authentication, scope, entitlement, and metering enforced at one edge gateway — every product and agent.

Subprocessors

Infrastructure & data

CloudflareEdge compute, CDN, storage, DNS, and AI inference (speech-to-text, embeddings) — SOC 2 Type II
SupabaseApplication database & authentication — SOC 2 Type II
UpstashRedis cache & message queue

Payments

StripePayments, subscriptions & metered billing — PCI DSS / SOC 2 Type II
BridgeStablecoin on/off-ramp & KYB verification
PrivyEmbedded & smart-wallet provisioning and key management
TempoStablecoin settlement (pathUSD)
Coinbase CDPWallet infrastructure & gas sponsorship
MetronomeUsage-based billing metering

Communications

TwilioInbound & outbound telephony and A2P messaging
ResendTransactional & notification email

Media & video

ZoomMeeting recording import, with your authorization

AI inference

DeepgramSpeech-to-text transcription
ElevenLabsText-to-speech voice synthesis
GroqLow-latency language-model inference

WAVE documents where data is stored and processed. See the Data Residency policy for specifics by region. Data Residency

Every commitment, in writing