Enterprise-grade security, by default
Security is not a feature at Engage — it's the foundation. From the way we store your data to how we handle access control, every layer is hardened to protect your business and your customers.
How we think about security
Security Focused
Defence-in-depth architecture with AES-256 encryption at rest, TLS 1.2/1.3 in transit, and role-based access control.
Privacy First
Data minimisation by design. We collect only what is needed, store it securely, and never sell or share your data with third parties.
Enterprise Ready
Full audit logs, multi-tenant data isolation, and role-based access control — architected to extend to SSO as we grow.
Infrastructure
Engage runs on AWS infrastructure (Mumbai, ap-south-1), with process-level health monitoring and automatic restart on every service.
- Hosted on AWS (Mumbai, ap-south-1)
- Automated daily backups with 30-day retention
- Per-organization data isolation, enforced at the query level
- Process-level health monitoring with automatic restart
- Point-in-time recovery Roadmap
Data Security
Your data is encrypted in transit and at rest. We use industry-standard algorithms and rotate keys regularly.
- TLS 1.2/1.3 encryption for all data in transit
- AES-256 encryption for data at rest
- Encrypted backups (S3 server-side encryption)
- No plaintext credential storage — bcrypt hashing
- Role-based access control with least privilege
- API keys scoped by workspace and permission level
Compliance & privacy
Data Privacy
- Minimal data collection policy
- Encrypted storage at rest and in transit
- Never sold or shared with third parties
DPDP Rights (India)
- Self-serve access, erasure & correction requests
- Request status tracking via secure link
- Consent capture with a full audit trail
- CSV export of consent records
WhatsApp Business Policy
- Opt-in only messaging — no cold outreach
- Meta-approved templates only
- Opt-out management built in
Access Control
- Short-lived access tokens (15 min) with refresh rotation
- Role-based access control
- API keys scoped by workspace and permission
- Multi-factor authentication (TOTP) Roadmap
- Google OAuth login Roadmap
Have security questions?
Happy to answer questions or walk through a vendor security questionnaire — reach out and we'll respond directly.