Security

Security at Waverly

Waverly is a performance marketing software platform. It holds campaign, measurement and payment records for brands, marketplace sellers and publishers, and — where a customer authorizes it — access to a connected commerce or advertising platform. This page describes the controls that are in place today. We do not list controls we have not implemented.

Encryption

Traffic between users, the Waverly application and its database is encrypted in transit using TLS. Data at rest, including connected-platform authorization tokens, is encrypted by the managed database and secret storage Waverly runs on.

Access controls

Every record in Waverly belongs to an organisation. Access is enforced in the database with row-level security, not only in the interface: a brand cannot read another brand's transactions, partners, invoices or settlements, and a partner cannot read another partner's earnings, links or payments. Access is denied by default unless the signed-in user owns the record or is a member of the Waverly operations team.

Role-based permissions

Roles are stored separately from user profiles and checked server-side. Brand and partner accounts have no access to internal notes, network-wide financial screens or other organisations' data. Administrative actions are restricted to the Waverly operations role.

Credential handling

Waverly never asks for a password to a connected platform. Authorizations use the platform's own authorization flow where available. Tokens and API credentials are held in server-side secret storage, are never sent to the browser, and are never written into application logs.

Integration failures

Authorization, synchronization and revocation events are logged with their outcome. A failed or partial synchronization is shown to the account owner and to the Waverly operations team rather than silently discarded, and financial records are never written from a failed integration call.

Audit trail

Approvals, rate changes, transaction adjustments, reversals, settlements, payouts and integration authorizations are recorded with the actor, timestamp, previous value, new value and reason. Audit history is read-only to normal users and cannot be edited or deleted from the application.

Incident response

Suspected incidents are triaged on receipt, contained, investigated and remediated. Affected customers are notified with what happened, what information was involved and what action is required, in line with applicable law and contractual commitments.

Data retention

Account and financial records are retained while the account is active and afterwards for tax, accounting and legal obligations. Operational logs are retained for a shorter period. Imported product and measurement data is retained only while it is needed to operate campaigns or support a financial record.

Connection revocation

A connected platform can be disconnected at any time from the integration settings page, or revoked with the platform directly. Waverly discards the stored authorization immediately, archives imported records and stops further synchronization. Measurement already used to calculate a payment is retained as a financial record.

Responsible disclosure

Security researchers are welcome to test against their own accounts. Please avoid accessing data that is not yours, degrading the service, or running automated scanning that affects other customers. We will acknowledge a report and keep you updated while we investigate.

Report a security issue

Use the address below to report a security vulnerability, suspected data exposure, or a compromised credential or authorization token. Include what you found, how to reproduce it and any account or record identifiers involved. If you believe a credential has been exposed, say so in the subject line so it is triaged first.

Security contact

security@waverly.io

Privacy contact

privacy@waverly.io

Legal entity

Waverly Network LLC