Security at Whale

At Whale, we prioritize not only technological advancement but also the ethical and responsible use of AI and data. We strive to ensure that our infrastructure fosters trust, transparency, and accountability, contributing to a more ethical, secure, and inclusive digital ecosystem globally.

Whale is SOC 2 compliant, GDPR compliant and HIPAA ready. Every control we hold is monitored continuously.

Security at Whale

Compliance at Whale

Whale follows global laws and security standards to meet compliance for our customers.

SOC 2 compliance badge
SOC 2
COMPLIANT
GDPR compliance badge
GDPR
COMPLIANT
HIPAA ready badge
HIPAA
READY

Trusted by the world's most trusted companies

Product security

These are the five product security controls Whale holds, in full.

Data encryption utilized

The company’s datastores housing sensitive customer data are encrypted at rest.

Control self-assessments conducted

The company performs control self-assessments at least annually to gain assurance that controls are in place and operating effectively. Corrective actions are taken based on relevant findings. If the company has committed to an SLA for a finding, the corrective action is completed within that SLA.

Penetration testing performed

The company’s penetration testing is performed at least annually. A remediation plan is developed and changes are implemented to remediate vulnerabilities in accordance with SLAs.

Data transmission encrypted

The company uses secure data transmission protocols to encrypt confidential and sensitive data when transmitted over public networks.

Vulnerability and system monitoring procedures established

The company’s formal policies outline the requirements for the following functions related to IT / Engineering: vulnerability management and system monitoring.

Continuously monitored controls

Whale monitors 53 controls across five areas, each one tracked continuously through Vanta.

Infrastructure security

19 controls monitored continuously.

Examples of the 19 controls in this area:

  • Unique production database authentication enforced
  • Encryption key access restricted
  • Unique account authentication enforced
  • Production network access restricted
  • Firewall access restricted
  • Access revoked upon termination

Organizational security

8 controls monitored continuously.

All 8 controls in this area:

  • Production inventory maintained
  • Portable media encrypted
  • Employee background checks performed
  • Confidentiality Agreement acknowledged by contractors
  • Confidentiality Agreement acknowledged by employees
  • Performance evaluations conducted
  • Password policy enforced
  • MDM system utilized

Product security

5 controls monitored continuously.

All 5 controls in this area:

  • Data encryption utilized
  • Control self-assessments conducted
  • Penetration testing performed
  • Data transmission encrypted
  • Vulnerability and system monitoring procedures established

Internal security procedures

20 controls monitored continuously.

Examples of the 20 controls in this area:

  • Cybersecurity insurance maintained
  • Configuration management system established
  • Whistleblower policy established
  • Board oversight briefings conducted
  • System changes externally communicated
  • Organization structure documented

Data and privacy

1 control monitored continuously.

The only control in this area:

  • Customer data deleted upon leaving

Privacy Policy on Whale

Our Privacy Policy, Terms and Conditions, and Cookie Policy are published openly, so you can read exactly how Whale collects, stores and processes your data before you commit to anything.

If your security or legal team needs something those documents do not cover, including our SOC 2 Type 2 report or our list of sub-processors, email security@usewhale.io and we will send it over.

Frequently asked questions

Whale is SOC 2 compliant, GDPR compliant and HIPAA ready, and we publish our security posture rather than simply describing it. Every control we hold is monitored continuously.

Our penetration testing is performed at least annually, and we perform control self-assessments at least annually to gain assurance that controls are in place and operating effectively. Our 2025-2026 SOC 2 Type 2 report, our security policies and our list of sub-processors are available on request. Email security@usewhale.io and we will send them over.

Whale is SOC 2 compliant, GDPR compliant and HIPAA ready.

Our 2025-2026 SOC 2 Type 2 report is available on request, alongside our Privacy Policy, our GDPR Compliance Policy and our list of sub-processors. Email security@usewhale.io to request them.

Whale holds five product security controls, monitored continuously:

  • Data encryption utilized. The company’s datastores housing sensitive customer data are encrypted at rest.
  • Control self-assessments conducted. The company performs control self-assessments at least annually to gain assurance that controls are in place and operating effectively. Corrective actions are taken based on relevant findings. If the company has committed to an SLA for a finding, the corrective action is completed within that SLA.
  • Penetration testing performed. The company’s penetration testing is performed at least annually. A remediation plan is developed and changes are implemented to remediate vulnerabilities in accordance with SLAs.
  • Data transmission encrypted. The company uses secure data transmission protocols to encrypt confidential and sensitive data when transmitted over public networks.
  • Vulnerability and system monitoring procedures established. The company’s formal policies outline the requirements for the following functions related to IT / Engineering: vulnerability management and system monitoring.