Security and Accountability at GBTick
Last updated: July 2026
Security and accountability are built into the GBTick operating model, not added as an afterthought. This page describes how we protect your data, your customers and your business.
Platform Security
GBTick uses HTTPS and TLS across all communications. Application security, dependency management and secure software development practices are applied throughout the development lifecycle. We maintain separate environments for development, staging and production.
Identity and Access
Role-based access control is applied at both platform and tenant level. Every team member is assigned the minimum permissions needed for their role. Session controls and revocation are in place, with multi-factor authentication direction in progress.
Tenant Isolation
Every company on GBTick is a separate tenant. Authorization policies ensure no cross-tenant data access. Chats, users, wallets, templates and analytics are fully isolated per company. Isolation controls are tested and reviewed.
Provider Credentials
WhatsApp Business API credentials and provider secrets are encrypted at rest. Access is restricted to authorized system processes. Credentials are never logged or displayed in plaintext. Rotation procedures are in place.
Messaging Integrity
Incoming webhooks are verified using signed signatures. Provider-assigned message IDs are used for deduplication and idempotency. Delivery statuses are recorded from the provider, not assumed. Retry and duplicate-protection mechanisms are in place.
Consent and Opt-Out
STOP commands from customers are recognized, recorded and applied to suppression lists. Opted-out contacts are excluded from future campaigns. Evidence of opt-out is retained. Re-opt-in requires explicit customer action.
Billing Integrity
Wallet transactions use a ledger model with reservations, debits, releases and refunds. All balance changes are traceable to the source event. Reconciliation tooling is included for agencies and enterprise accounts.
Data Lifecycle
Customer data is collected for the minimum purposes necessary. Retention periods, deletion, export and portability options are available. Backups are maintained. Customers retain ownership of their contact and conversation data.
Incident Management
Security incidents are triaged against a documented response process. Affected customers are notified in accordance with our notification policy. A status page is maintained for service transparency. Responsible disclosure is welcome via our security contact.
Responsible Disclosure
If you discover a security vulnerability in GBTick, please contact us at security@gbtick.com. We ask that you give us reasonable time to investigate before public disclosure. We will acknowledge receipt within 3 business days.
Subprocessors
GBTick uses third-party subprocessors for hosting, CDN, object storage, analytics, email, support tooling, AI services and WhatsApp/BSP provider connectivity. A current list of subprocessors is maintained at /subprocessors.