Security by Architecture.
KopasAI is built on a "Defense-in-Depth" model, ensuring that every conversational byte is isolated, encrypted, and governed by industrial-grade protocols.
Sovereign Logic Flow
User Port
Messages arrive over HTTPS from the WhatsApp Cloud API, with each webhook request signature-verified.
Access Layer
Authenticated requests only, with rate limiting and login lockout on repeated failures.
Sovereign Core
AES-256 encryption at rest, with channel credentials envelope-encrypted via Cloud KMS.
Envelope-Encrypted Credentials
Channel access tokens and OAuth secrets are envelope-encrypted with Google Cloud KMS before they are written to the database, using a dedicated key per channel integration.
Encrypted in Transit and at Rest
Traffic is served over TLS 1.3, and stored data is encrypted at rest with AES-256 through Google Cloud's platform storage encryption.
Hosted in Southeast Asia
Merchant data is stored in Google Cloud regional infrastructure. AI model inference is performed by Google and may be processed in other regions. Merchant business data is never used to train public AI models.
Per-Merchant
Data Separation.
Every record in KopasAI is scoped to a merchant tenant key, and every authenticated request is resolved against the merchant it belongs to — so one merchant's customers, orders, and channel credentials are never served to another.
Reporting a Security Issue
Found a vulnerability? Get in touch and we will look into it. Please give us a reasonable window to respond before disclosing publicly.
Report a VulnerabilityQuestions about security?
Our privacy policy sets out exactly what we store, where we store it, how long we keep it, and how to have it deleted.