Security at Whale

At Whale, we prioritize not only technological advancement but also the ethical and responsible use of AI and data. We strive to ensure that our infrastructure fosters trust, transparency, and accountability, contributing to a more ethical, secure, and inclusive digital ecosystem globally.

Whale is SOC 2 compliant, GDPR compliant and HIPAA ready. Every control we hold is monitored continuously.

Security at Whale

Compliance at Whale

Whale follows global laws and security standards to meet compliance for our customers.

SOC 2 compliance badge
SOC 2
COMPLIANT
GDPR compliance badge
GDPR
COMPLIANT
HIPAA ready badge
HIPAA
READY

Trusted by the world's most trusted companies

Product security

These are the five product security controls Whale holds, in full.

Data encryption utilized

The company’s datastores housing sensitive customer data are encrypted at rest.

Control self-assessments conducted

The company performs control self-assessments at least annually to gain assurance that controls are in place and operating effectively. Corrective actions are taken based on relevant findings. If the company has committed to an SLA for a finding, the corrective action is completed within that SLA.

Penetration testing performed

The company’s penetration testing is performed at least annually. A remediation plan is developed and changes are implemented to remediate vulnerabilities in accordance with SLAs.

Data transmission encrypted

The company uses secure data transmission protocols to encrypt confidential and sensitive data when transmitted over public networks.

Vulnerability and system monitoring procedures established

The company’s formal policies outline the requirements for the following functions related to IT / Engineering: vulnerability management and system monitoring.

Continuously monitored controls

Whale monitors 51 controls across five areas, each one tracked continuously through Vanta.

Infrastructure security

19 controls monitored continuously.

Examples of the 19 controls in this area:

  • Unique production database authentication enforced
  • Encryption key access restricted
  • Unique account authentication enforced
  • Production network access restricted
  • Firewall access restricted
  • Access revoked upon termination

Organizational security

7 controls monitored continuously.

All 7 controls in this area:

  • Production inventory maintained
  • Employee background checks performed
  • Confidentiality Agreement acknowledged by contractors
  • Confidentiality Agreement acknowledged by employees
  • Performance evaluations conducted
  • Password policy enforced
  • MDM system utilized

Product security

5 controls monitored continuously.

All 5 controls in this area:

  • Data encryption utilized
  • Control self-assessments conducted
  • Penetration testing performed
  • Data transmission encrypted
  • Vulnerability and system monitoring procedures established

Internal security procedures

19 controls monitored continuously.

Examples of the 19 controls in this area:

  • Third-party agreements established
  • Configuration management system established
  • Whistleblower policy established
  • Board oversight briefings conducted
  • System changes externally communicated
  • Organization structure documented

Data and privacy

1 control monitored continuously.

The only control in this area:

  • Customer data deleted upon leaving

What each control actually does

Below is the substance behind the badges: the specific mechanisms behind our encryption, our network, our access control, our AI commitments and the people who operate them.

Diagram: customer content encrypted with AES-256 at rest and TLS 1.2 or higher in transit, with encryption key access restricted
PRODUCT SECURITY

Encryption everywhere your data sits or moves

Every datastore holding sensitive customer content is encrypted at rest, every connection is encrypted in transit, and access to the keys that protect it is restricted.

AT REST

Datastores housing sensitive customer data are encrypted at rest, using AES-256.

IN TRANSIT

TLS 1.2 or higher. Confidential and sensitive data is encrypted whenever it is transmitted over public networks.

KEY ACCESS

Privileged access to encryption keys is restricted to authorized users with a business need.

REMOTE ACCESS

Production systems can only be reached over an approved encrypted connection, by authorized employees with a valid multi-factor authentication method.

ASSURANCE

Control self-assessments run at least annually, and corrective actions are completed inside the SLA we have committed to.

INFRASTRUCTURE SECURITY

One way in, and it is watched

The production network is segmented, the ways into it are restricted and authenticated, and what happens inside is monitored for events with security impact.

SEGMENTATION

The production network is segmented to prevent unauthorized access to customer data.

PERIMETER

Firewalls are configured to prevent unauthorized access. Privileged access to the firewall is restricted, and firewall rulesets are reviewed at least annually.

INGRESS

Privileged access to the production network, databases, operating systems and the production application is restricted to authorized users with a business need.

MONITORING

An infrastructure monitoring tool watches systems, infrastructure and performance, and generates alerts when predefined thresholds are met.

LOGGING

A log management tool identifies events that may have a potential impact on our security objectives.

HARDENING

Network and system hardening standards are documented, based on industry best practices and reviewed at least annually. Infrastructure is patched as part of routine maintenance and in response to identified vulnerabilities.

Diagram: a firewall around a segmented Whale production network, blocking unauthorised ingress and allowing encrypted connections
Diagram: multi-factor authentication gating role baseline access, request plus manager approval, or no access
ACCESS CONTROL

Nobody has standing access to your content

Access follows role and business need, never convenience. The privileged paths to production, to databases, to the firewall and to encryption keys are gated behind multi-factor authentication.

AUTHENTICATION

Multi-factor authentication is required for privileged access to production systems. Authentication uses unique usernames and passwords or authorized SSH keys.

AUTHORIZATION

Access is granted on a least-privilege, role-based basis. Anything beyond a role’s baseline needs a documented access request and manager approval before it is provisioned.

PASSWORDS

Passwords for in-scope system components are configured according to our password policy.

OFFBOARDING

A termination checklist is completed for every leaver, so that access is revoked inside our committed SLA.

WHEN YOU LEAVE

Customer data containing confidential information is purged or removed from the application environment when customers leave the service.

AI AND YOUR DATA

Your content never trains anyone's model. Ours included.

Whale’s AI features run on your documentation to help you write and maintain it. That is the only thing they do with it, and it is a contractual commitment in our Terms rather than a setting you have to find and switch off.

No training on our models

We do not use your content, prompts, documents or outputs to train, fine-tune or improve our own algorithms or machine-learning models.

No training by our providers

We do not permit third-party AI providers to use your content to train their models, and our written agreements with vendors carry confidentiality and privacy commitments.

Metadata only, never substance

We use technical metadata such as feature usage frequency and system logs to optimize the service. That is separate from the substance of what you write.

Aggregate insight stays anonymous

Anonymized, aggregated data is used for product improvement only where it cannot reasonably identify you or any individual.

ORGANIZATIONAL SECURITY

The people with access are vetted and bound

Everyone who can reach customer data is screened before they start, contractually bound to keep it confidential, and working from a device we manage centrally.

SCREENING

Background checks are performed on new employees.

CONTRACTS

Employees sign a confidentiality agreement during onboarding, and contractors sign one at the time of engagement.

DEVICES

A mobile device management system centrally manages the devices that support the service.

ASSETS

A formal inventory of production system assets is maintained.

ACCOUNTABILITY

Roles and responsibilities for designing, operating and monitoring information security controls are formally assigned in job descriptions and our Roles and Responsibilities policy.

Diagram: everyone who can reach customer data has a background check, a confidentiality agreement and an MDM-managed device

Privacy Policy on Whale

Our Privacy Policy, Terms and Conditions, and Cookie Policy are published openly, so you can read exactly how Whale collects, stores and processes your data before you commit to anything.

If your security or legal team needs something those documents do not cover, including our SOC 2 Type 2 report or our list of sub-processors, email security@usewhale.io and we will send it over.

Frequently asked questions

Whale is SOC 2 compliant, GDPR compliant and HIPAA ready, and we publish our security posture rather than simply describing it. Every control we hold is monitored continuously.

Our penetration testing is performed at least annually, and we perform control self-assessments at least annually to gain assurance that controls are in place and operating effectively. Our 2025-2026 SOC 2 Type 2 report, our security policies and our list of sub-processors are available on request. Email security@usewhale.io and we will send them over.

Whale is SOC 2 compliant, GDPR compliant and HIPAA ready.

Our 2025-2026 SOC 2 Type 2 report is available on request, alongside our Privacy Policy, our GDPR Compliance Policy and our list of sub-processors. Email security@usewhale.io to request them.

Whale holds five product security controls, monitored continuously:

  • Data encryption utilized. The company’s datastores housing sensitive customer data are encrypted at rest.
  • Control self-assessments conducted. The company performs control self-assessments at least annually to gain assurance that controls are in place and operating effectively. Corrective actions are taken based on relevant findings. If the company has committed to an SLA for a finding, the corrective action is completed within that SLA.
  • Penetration testing performed. The company’s penetration testing is performed at least annually. A remediation plan is developed and changes are implemented to remediate vulnerabilities in accordance with SLAs.
  • Data transmission encrypted. The company uses secure data transmission protocols to encrypt confidential and sensitive data when transmitted over public networks.
  • Vulnerability and system monitoring procedures established. The company’s formal policies outline the requirements for the following functions related to IT / Engineering: vulnerability management and system monitoring.