Security and Accountability at GBTick

Last updated: July 2026

Security and accountability are built into the GBTick operating model, not added as an afterthought. This page describes how we protect your data, your customers and your business.

Important: GBTick does not claim ISO 27001, SOC 2, GDPR, or similar certifications unless separately stated and verified. WhatsApp is a trademark of Meta Platforms, Inc. GBTick is an independent platform.

Platform Security

GBTick uses HTTPS and TLS across all communications. Application security, dependency management and secure software development practices are applied throughout the development lifecycle. We maintain separate environments for development, staging and production.

Identity and Access

Role-based access control is applied at both platform and tenant level. Every team member is assigned the minimum permissions needed for their role. Session controls and revocation are in place, with multi-factor authentication direction in progress.

Tenant Isolation

Every company on GBTick is a separate tenant. Authorization policies ensure no cross-tenant data access. Chats, users, wallets, templates and analytics are fully isolated per company. Isolation controls are tested and reviewed.

Provider Credentials

WhatsApp Business API credentials and provider secrets are encrypted at rest. Access is restricted to authorized system processes. Credentials are never logged or displayed in plaintext. Rotation procedures are in place.

Messaging Integrity

Incoming webhooks are verified using signed signatures. Provider-assigned message IDs are used for deduplication and idempotency. Delivery statuses are recorded from the provider, not assumed. Retry and duplicate-protection mechanisms are in place.

Consent and Opt-Out

STOP commands from customers are recognized, recorded and applied to suppression lists. Opted-out contacts are excluded from future campaigns. Evidence of opt-out is retained. Re-opt-in requires explicit customer action.

Billing Integrity

Wallet transactions use a ledger model with reservations, debits, releases and refunds. All balance changes are traceable to the source event. Reconciliation tooling is included for agencies and enterprise accounts.

Data Lifecycle

Customer data is collected for the minimum purposes necessary. Retention periods, deletion, export and portability options are available. Backups are maintained. Customers retain ownership of their contact and conversation data.

Incident Management

Security incidents are triaged against a documented response process. Affected customers are notified in accordance with our notification policy. A status page is maintained for service transparency. Responsible disclosure is welcome via our security contact.

Responsible Disclosure

If you discover a security vulnerability in GBTick, please contact us at security@gbtick.com. We ask that you give us reasonable time to investigate before public disclosure. We will acknowledge receipt within 3 business days.

Subprocessors

GBTick uses third-party subprocessors for hosting, CDN, object storage, analytics, email, support tooling, AI services and WhatsApp/BSP provider connectivity. A current list of subprocessors is maintained at /subprocessors.