Not sure where to start?
At Whale, we prioritize not only technological advancement but also the ethical and responsible use of AI and data. We strive to ensure that our infrastructure fosters trust, transparency, and accountability, contributing to a more ethical, secure, and inclusive digital ecosystem globally.
Whale is SOC 2 compliant, GDPR compliant and HIPAA ready. Every control we hold is monitored continuously.
Whale follows global laws and security standards to meet compliance for our customers.
These are the five product security controls Whale holds, in full.
The company’s datastores housing sensitive customer data are encrypted at rest.
The company performs control self-assessments at least annually to gain assurance that controls are in place and operating effectively. Corrective actions are taken based on relevant findings. If the company has committed to an SLA for a finding, the corrective action is completed within that SLA.
The company’s penetration testing is performed at least annually. A remediation plan is developed and changes are implemented to remediate vulnerabilities in accordance with SLAs.
The company uses secure data transmission protocols to encrypt confidential and sensitive data when transmitted over public networks.
The company’s formal policies outline the requirements for the following functions related to IT / Engineering: vulnerability management and system monitoring.
Whale monitors 51 controls across five areas, each one tracked continuously through Vanta.
19 controls monitored continuously.
Examples of the 19 controls in this area:
7 controls monitored continuously.
All 7 controls in this area:
5 controls monitored continuously.
All 5 controls in this area:
19 controls monitored continuously.
Examples of the 19 controls in this area:
1 control monitored continuously.
The only control in this area:
Below is the substance behind the badges: the specific mechanisms behind our encryption, our network, our access control, our AI commitments and the people who operate them.
Every datastore holding sensitive customer content is encrypted at rest, every connection is encrypted in transit, and access to the keys that protect it is restricted.
Datastores housing sensitive customer data are encrypted at rest, using AES-256.
TLS 1.2 or higher. Confidential and sensitive data is encrypted whenever it is transmitted over public networks.
Privileged access to encryption keys is restricted to authorized users with a business need.
Production systems can only be reached over an approved encrypted connection, by authorized employees with a valid multi-factor authentication method.
Control self-assessments run at least annually, and corrective actions are completed inside the SLA we have committed to.
The production network is segmented, the ways into it are restricted and authenticated, and what happens inside is monitored for events with security impact.
The production network is segmented to prevent unauthorized access to customer data.
Firewalls are configured to prevent unauthorized access. Privileged access to the firewall is restricted, and firewall rulesets are reviewed at least annually.
Privileged access to the production network, databases, operating systems and the production application is restricted to authorized users with a business need.
An infrastructure monitoring tool watches systems, infrastructure and performance, and generates alerts when predefined thresholds are met.
A log management tool identifies events that may have a potential impact on our security objectives.
Network and system hardening standards are documented, based on industry best practices and reviewed at least annually. Infrastructure is patched as part of routine maintenance and in response to identified vulnerabilities.
Access follows role and business need, never convenience. The privileged paths to production, to databases, to the firewall and to encryption keys are gated behind multi-factor authentication.
Multi-factor authentication is required for privileged access to production systems. Authentication uses unique usernames and passwords or authorized SSH keys.
Access is granted on a least-privilege, role-based basis. Anything beyond a role’s baseline needs a documented access request and manager approval before it is provisioned.
Passwords for in-scope system components are configured according to our password policy.
A termination checklist is completed for every leaver, so that access is revoked inside our committed SLA.
Customer data containing confidential information is purged or removed from the application environment when customers leave the service.
Whale’s AI features run on your documentation to help you write and maintain it. That is the only thing they do with it, and it is a contractual commitment in our Terms rather than a setting you have to find and switch off.
We do not use your content, prompts, documents or outputs to train, fine-tune or improve our own algorithms or machine-learning models.
We do not permit third-party AI providers to use your content to train their models, and our written agreements with vendors carry confidentiality and privacy commitments.
We use technical metadata such as feature usage frequency and system logs to optimize the service. That is separate from the substance of what you write.
Anonymized, aggregated data is used for product improvement only where it cannot reasonably identify you or any individual.
Everyone who can reach customer data is screened before they start, contractually bound to keep it confidential, and working from a device we manage centrally.
Background checks are performed on new employees.
Employees sign a confidentiality agreement during onboarding, and contractors sign one at the time of engagement.
A mobile device management system centrally manages the devices that support the service.
A formal inventory of production system assets is maintained.
Roles and responsibilities for designing, operating and monitoring information security controls are formally assigned in job descriptions and our Roles and Responsibilities policy.
Our Privacy Policy, Terms and Conditions, and Cookie Policy are published openly, so you can read exactly how Whale collects, stores and processes your data before you commit to anything.
If your security or legal team needs something those documents do not cover, including our SOC 2 Type 2 report or our list of sub-processors, email security@usewhale.io and we will send it over.
Whale is SOC 2 compliant, GDPR compliant and HIPAA ready, and we publish our security posture rather than simply describing it. Every control we hold is monitored continuously.
Our penetration testing is performed at least annually, and we perform control self-assessments at least annually to gain assurance that controls are in place and operating effectively. Our 2025-2026 SOC 2 Type 2 report, our security policies and our list of sub-processors are available on request. Email security@usewhale.io and we will send them over.
Whale is SOC 2 compliant, GDPR compliant and HIPAA ready.
Our 2025-2026 SOC 2 Type 2 report is available on request, alongside our Privacy Policy, our GDPR Compliance Policy and our list of sub-processors. Email security@usewhale.io to request them.
Whale holds five product security controls, monitored continuously: