Security
Control before action.
Wopie is built so credentials stay sealed, every sensitive action waits for a human, and your workspace data does your work and nothing else.
Approvals and permissions
Autonomous where it's safe. Paused where it matters.
Every channel gets rules. Internal work runs on its own. Anything external, financial or irreversible waits for a human, and every decision lands in the audit trail.
Permission rules
#sales · set by adminsAudit trail
- Every decision is recorded here with who, what and when.
Each one references the last conversation and the open question, not a template. 7 follow-ups written.
Paused. These send from each owner's inbox. Each owner reviews and edits their own before anything sends.
ApproveEditEvery approval, edit and rejection is recorded with who, what and when.
- SOC 2-ready controlsControls mapped to SOC 2 criteria; audit evidence available for review.
- ISO 27001-aligned policiesSecurity policies written against the ISO 27001 control set.
- GDPR-aware data handlingData minimisation, export and deletion on request, EU-aware processing.
- DPA publishedOur data processing agreement is public at wopie.ai/legal/dpa and can be countersigned for your procurement review.
- SSO / SAML-readySingle sign-on flows ready for identity-provider setup.
- Audit trail availableEvery delegated request, output and approval is recorded.
- Built on independently audited providersAWS, Vercel, Supabase, Anthropic, Slack, Microsoft and Stripe each hold their own SOC 2 and/or ISO 27001 attestations for the layers they run. Those are theirs, not ours; Wopie's own attestation is in progress.
Where your data lives
Scoped, sealed, and yours.
Credentials stay sealed
Connected-tool credentials are encrypted and access-limited. The model works through scoped access, never with raw secrets.
Scope follows your permissions
Wopie only sees channels it's invited to, and only acts in tools through the access your team already has.
Your data does your work, nothing else
Workspace content is used to prepare what you asked for. It is not used to train foundation models, and it's deleted on request.
What it does, what it never does
Autonomous, not unsupervised.
What Wopie does
- Encrypts connected-tool credentials and limits who can use them
- Pauses external sends and risky actions for a human approval
- Keeps each workspace and channel scoped to its own permissions
- Keeps an audit trail of every request, output and approval
- Offers SSO/SAML-ready sign-in and a published, signable DPA
What Wopie never does
- Send a sensitive action without a human approval
- Read a channel it hasn't been invited to
- Train foundation models on your workspace data
- Expose raw credentials to the model
- Retain data after you've asked for it to be deleted
Readiness
Precise language for your security review.
We describe our posture exactly. Where a certification is not yet held, we say ready or aligned, not certified.
| Area | Status |
|---|---|
| SOC 2-ready controls | Controls mapped to SOC 2 criteria; audit evidence available for review. |
| ISO 27001-aligned policies | Security policies written against the ISO 27001 control set. |
| GDPR-aware data handling | Data minimisation, export and deletion on request, EU-aware processing. |
| DPA published | Our data processing agreement is public at wopie.ai/legal/dpa and can be countersigned for your procurement review. |
| SSO / SAML-ready | Single sign-on flows ready for identity-provider setup. |
| Audit trail available | Every delegated request, output and approval is recorded. |
| Built on independently audited providers | AWS, Vercel, Supabase, Anthropic, Slack, Microsoft and Stripe each hold their own SOC 2 and/or ISO 27001 attestations for the layers they run. Those are theirs, not ours; Wopie's own attestation is in progress. |
Questions
Security questions, answered.
It proposes, you decide. Every external, financial or irreversible action waits for an explicit approval. Deletions never run.