At Whale, we prioritize not only technological advancement but also the ethical and responsible use of AI and data. We strive to ensure that our infrastructure fosters trust, transparency, and accountability, contributing to a more ethical, secure, and inclusive digital ecosystem globally.
Whale is SOC 2 compliant, GDPR compliant and HIPAA ready. Every control we hold is monitored continuously.
Whale follows global laws and security standards to meet compliance for our customers.
These are the five product security controls Whale holds, in full.
The company’s datastores housing sensitive customer data are encrypted at rest.
The company performs control self-assessments at least annually to gain assurance that controls are in place and operating effectively. Corrective actions are taken based on relevant findings. If the company has committed to an SLA for a finding, the corrective action is completed within that SLA.
The company’s penetration testing is performed at least annually. A remediation plan is developed and changes are implemented to remediate vulnerabilities in accordance with SLAs.
The company uses secure data transmission protocols to encrypt confidential and sensitive data when transmitted over public networks.
The company’s formal policies outline the requirements for the following functions related to IT / Engineering: vulnerability management and system monitoring.
Whale monitors 53 controls across five areas, each one tracked continuously through Vanta.
19 controls monitored continuously.
Examples of the 19 controls in this area:
8 controls monitored continuously.
All 8 controls in this area:
5 controls monitored continuously.
All 5 controls in this area:
20 controls monitored continuously.
Examples of the 20 controls in this area:
1 control monitored continuously.
The only control in this area:
Our Privacy Policy, Terms and Conditions, and Cookie Policy are published openly, so you can read exactly how Whale collects, stores and processes your data before you commit to anything.
If your security or legal team needs something those documents do not cover, including our SOC 2 Type 2 report or our list of sub-processors, email security@usewhale.io and we will send it over.
Whale is SOC 2 compliant, GDPR compliant and HIPAA ready, and we publish our security posture rather than simply describing it. Every control we hold is monitored continuously.
Our penetration testing is performed at least annually, and we perform control self-assessments at least annually to gain assurance that controls are in place and operating effectively. Our 2025-2026 SOC 2 Type 2 report, our security policies and our list of sub-processors are available on request. Email security@usewhale.io and we will send them over.
Whale is SOC 2 compliant, GDPR compliant and HIPAA ready.
Our 2025-2026 SOC 2 Type 2 report is available on request, alongside our Privacy Policy, our GDPR Compliance Policy and our list of sub-processors. Email security@usewhale.io to request them.
Whale holds five product security controls, monitored continuously: