Security & compliance

Tenashi (“Tenashi”, “we”, “us”) provides a shared WhatsApp workspace — inbox, CRM, and support desk — for teams. Your conversations, contacts, and customer data run through us, so protecting them is core to what we do. This page explains how we approach security, what our infrastructure gives us, and where we are honest about the limits of our current posture.

In short: we host entirely on Amazon Web Services (AWS), whose infrastructure is independently audited and holds SOC 2 Type II and ISO 27001 certifications. We encrypt data in transit, isolate each workspace’s data, and restrict internal access to what is needed to operate the service. To be clear, Tenashi has not yet completed an independent SOC 2 audit of its own; the SOC 2 and ISO certifications described below belong to our infrastructure provider, AWS.

Infrastructure

Tenashi runs entirely on Amazon Web Services (AWS). AWS data centres are independently audited and hold SOC 2 Type II and ISO 27001 certifications, among others. By building on AWS we inherit the physical security of their facilities — access controls, surveillance, environmental protections — and the network-level protections of their platform.

This means the foundation our service sits on is operated to a standard that is independently verified. It does not mean Tenashi itself has been audited to those standards; the certifications are AWS’s, and they cover the infrastructure layer we depend on.

Data protection

Access control

Internally, we follow the principle of least privilege: team members get only the access their role requires, and administrative access to production systems is limited and controlled. All accounts require authentication, and within a workspace we support role-based permissions so you can decide who on your team can see and do what.

GDPR & privacy

Tenashi is GDPR compliant: we process personal data lawfully, honour data-subject rights such as access and erasure, and hold data-processing terms with our sub-processors. For the full detail, see our GDPR statement and our Privacy Policy, which explain what we process, why, and the choices you have.

WhatsApp session safety

Tenashi automates a real WhatsApp session on your behalf, so protecting the numbers you connect matters as much as protecting your data. We apply anti-ban measures designed to keep connected numbers healthy — warm-up caps that ramp sending volume gradually, and human-paced sending that avoids the burst patterns that trigger blocks.

The session credentials that keep your number connected are handled carefully and are never shared across workspaces. You remain responsible for messaging only contacts you are permitted to reach and for following WhatsApp’s own policies.

Reliability

We take regular backups of your data, monitor our systems for failures and unusual activity, and aim for high availability. Because Tenashi depends on WhatsApp — a third-party service we do not control — we cannot guarantee uninterrupted operation, but we work to keep the service stable and to recover quickly when problems occur.

Reporting a vulnerability

If you believe you have found a security issue in Tenashi, please email us at hello@usetenashi.com. We take reports seriously, investigate promptly, and will work with you to understand and resolve the issue. Please give us a reasonable opportunity to address a problem before disclosing it publicly.

Contact

For any security or compliance question, reach us at hello@usetenashi.com and we’ll be glad to help.