Security

How we protect your clinic's accounts, data, and client information.

Our Security Approach

Security is fundamental to how we build and operate the AI DM Concierge. We understand that you're trusting us with access to your social accounts and client conversations, and we take that responsibility seriously.

Official APIs Only

We connect via Meta and WhatsApp's official Business APIs — no screen scraping or unofficial access methods.

Least-Privilege Access

We only request the minimum permissions needed to operate. We never ask for more access than necessary.

No Password Storage

We use OAuth tokens for account access. Your passwords are never shared with or stored by us.

Encrypted Connections

All data is encrypted in transit using TLS. Data at rest is encrypted using industry-standard methods.

Account Protection

Your Instagram and WhatsApp accounts remain under your control:

  • You grant access: Via official platform authorization flows
  • You can revoke access: At any time through platform settings or by contacting us
  • We log all actions: Audit trail of what the system does on your behalf
  • Immediate removal: Upon service termination, access is revoked promptly

Data Handling

We handle your data with care:

  • Message content: Processed in real-time; logs retained for 90 days for service quality
  • Booking data: Stored securely for the duration of our service relationship
  • Analytics: Aggregated data used to generate your Weekly Revenue Scorecard
  • No selling: We never sell or share your data for advertising purposes

Infrastructure Security

  • Hosted on reputable cloud providers with strong security track records
  • Regular security updates and patch management
  • Secure credential management (no hard-coded secrets)
  • Access controls limiting who can view sensitive data
  • Regular backups with secure storage

Compliance

  • GDPR-compliant data processing for UK and EEA clients
  • Meta and WhatsApp Business Platform policies compliance
  • Data processing agreements available upon request

Incident Response

In the unlikely event of a security incident:

  • We will notify affected clients promptly (within 72 hours for GDPR-relevant incidents)
  • We will investigate thoroughly and implement remediation
  • We will provide clear communication about what happened and next steps

Questions or Concerns

If you have security questions or want to report a concern, contact us.

Last updated: January 2026

Book a Free Demo