Plain-English answers to the questions enterprise buyers ask before they sign — how we encrypt, who has access, where the data lives, and how to report a vulnerability.
HttpOnly, Secure, SameSitecookies — not accessible from JavaScript and not exposed to XSS.dangerouslySetInnerHTML on user-supplied content.We use a small set of well-known vendors to operate the platform. Each vendor, the data they process, their region, and a link to their DPA, is published on our Sub-processors page. We update that page when we add or remove a vendor.
If you believe you have found a security issue, please email hello@whatrite.dev with the subject line “Security disclosure” and as much detail as you can share — affected endpoint, reproduction steps, and your contact for follow-up.
We commit to acknowledging within 3 business days and to keeping you informed while we investigate. We will not pursue legal action against researchers who follow good-faith responsible disclosure: avoid privacy violations, don't degrade service for other users, and give us reasonable time to fix the issue before going public.