Compliance Readiness
This page summarizes WALO's current compliance posture and the controls planned for broader enterprise review. It is written to help legal, security, customers, and future auditors understand what exists now, what depends on connected providers, and what will be formalized next.
Current posture plus planned controls
Privacy Policy, Cookie Notice, data rights language, advertising disclosures, connected-account disclosures, and customer-content posture are drafted for counsel review.
Access control, scoped OAuth, approval gates, tenant separation, secret handling, logs, incident reporting, and connected-provider governance are documented.
WALO documents AI training posture, user approvals, provider limits, output review, sensitive-action gates, and high-risk workflow restrictions.
Subprocessors are listed by purpose, including hosting, AI, messaging, email, payments, recognition, browser verification, and connected accounts.
Current documents
- Privacy Policy covering data collected, use, sharing, rights, cookies, advertising, AI processing, international transfers, and customer content.
- Terms of Service covering accounts, connected services, messaging, AI outputs, acceptable use, payments, disputes, disclaimers, and user responsibilities.
- Security Controls covering access, OAuth, secrets, logs, tenant separation, AI controls, reliability, browser verification, and incidents.
- Cookie Notice, Acceptable Use Policy, Data Processing Addendum overview, and Subprocessor list.
Governance controls
- App access controls: allowlist and blocklist policy for apps, providers, repos, domains, tools, and browser automation lanes.
- Action restrictions: endpoint-level controls for DNS, deploy, Git commit, payment, public posting, customer messaging, export, and admin actions.
- Managed connections: company-owned credentials and workspace-level OAuth connections can be kept separate from personal user accounts.
- Domain restrictions: teams can require approved domains or managed accounts and block personal accounts where needed.
- AI model policies: BYOM configuration can support approved providers, customer-owned model keys, local models, model allowlists, or model blocklists when that workspace requires it.
Planned compliance work
- SOC 2: WALO does not currently claim SOC 2 certification. SOC 2 Type II readiness can be started when production controls, audit evidence, access reviews, vendor reviews, incident response, change management, and monitoring are consistently operating.
- SOC 3: WALO does not currently claim SOC 3. A public SOC 3 report can be considered after SOC 2 controls are mature and an auditor supports issuing a public report.
- Enterprise governance: team approvals, role-based access, audit logs, connector allowlists, model/provider allowlists, data retention settings, and admin review exports should be formalized for higher-volume customers.
- Messaging compliance: WhatsApp and email workflows should continue to require consent, approved templates where required, opt-out handling, sender identity, and records of user-requested sends.
- AI and media processing: transcription, Song Seeker, image review, site review, and browser verification should keep raw media request-scoped unless a user explicitly saves output or metadata.
Controls to evidence before audit
- Access reviews for production systems, provider accounts, repositories, and admin consoles.
- Change management records for code changes, environment changes, DNS changes, and production releases.
- Incident response process with severity, owner, timeline, customer notice decision, remediation, and post-incident review.
- Subprocessor review records, provider terms, security posture, and data handling notes.
- Backups, retention settings, deletion workflows, export workflows, and restore tests where applicable.
- Logging and monitoring for authentication events, sensitive actions, failed provider calls, retries, and admin activity.
No certification claim: This page does not state that WALO is SOC 2, SOC 3, ISO 27001, HIPAA, PCI, or Data Privacy Framework certified. Those claims should only be added after the relevant formal certification, attestation, listing, or agreement is complete.
Review note
This page is a compliance-readiness overview and operational drafting aid. It should be reviewed by qualified legal, privacy, and security counsel before being used as a final customer-facing compliance statement.
Back to Legal Center