Security
Security
How HERE protects your data — encryption, access, incident response and vulnerability disclosure.
Effective: 12 September 2026
1. Our approach
HERE keeps things people would rather not lose — reminders, customer records, family details, receipts. Security is therefore not a checklist for us; it is the product. This page explains what we actually do, and what we don't yet claim.
2. Encryption
- At rest: all user data is encrypted using AES-256 with keys managed by Google Cloud KMS. Voice and image media are encrypted before being written to storage.
- In transit: all traffic between the WhatsApp Business API, our services, and the user is over TLS 1.2 or higher. Internal service-to-service traffic within Google Cloud VPC also enforces TLS.
- Secrets: API keys and credentials for third-party processors are held in Google Cloud Secret Manager and rotated on a defined schedule.
3. Access control
- Access to production systems is limited to a short list of engineers and requires multi-factor authentication.
- All administrative access is logged and reviewed monthly.
- Service accounts use short-lived, audited credentials issued via workload identity federation.
- The principle of least privilege is applied across roles; no engineer has blanket read access to user content.
4. Infrastructure and data residency
HERE runs on Google Cloud Platform in the India (Mumbai) asia-south1 region. User data does not leave India except for the specific processors listed in our Privacy Policy. Backups are region-local. We do not currently use multi-region replication for user data.
Voice notes are transcribed by Sarvam AI. Images are analysed by Google Gemini. Both processors operate under contractual restrictions preventing them from using your data for their own purposes or combining it with other customers' data.
5. People and process
- All personnel with production access complete a security induction and re-attest annually.
- Every code change goes through peer review before being deployed.
- Third-party dependencies are scanned continuously for known vulnerabilities and patched on a risk-based schedule.
- We do not send production data to non-production environments. Staging environments use synthetic data only.
6. Vulnerability disclosure
If you believe you have found a security vulnerability in HERE — the WhatsApp assistant, this website, or any HERE service — we would like to hear about it before it's disclosed publicly.
- Please email info@trenlytics.com with subject line "Security: [brief description]".
- We acknowledge every valid report within one business day.
- Please give us reasonable time to investigate and fix (typically 30-90 days depending on severity) before public disclosure.
- We do not currently run a paid bug-bounty programme, but we will credit you in a public disclosure if you would like.
- Do not access or modify data belonging to other users, disrupt the service, or perform tests that could damage anyone. Good-faith research on your own account is welcome.
7. Incident response
In the event of a security incident affecting user data, we will:
- Contain and remediate the incident as our first priority.
- Notify affected users within 72 hours of confirmation, describing what happened, what data was involved, and what we are doing about it.
- Notify the CERT-In (India Computer Emergency Response Team) within the timelines mandated by the CERT-In Directions of April 2022.
- Publish a public postmortem after the incident is fully contained, with reasonable technical detail and a description of the fixes.
8. Compliance posture
We do not claim what we don't have. Here is where we stand today:
- DPDP Act (India) — our processes align with the DPDP Act as it comes into force; we operate our Privacy Policy under its framework.
- SOC 2 / ISO 27001 — not currently certified. If your organisation needs formal attestation before adopting HERE Pro, contact us early. We can share our current controls, our roadmap toward certification, and accommodate specific requirements in the HERE Pro contract.
- PCI DSS — we do not store card numbers; card handling is the responsibility of our PCI-DSS-Level-1-certified provider Cashfree.
- Data localisation for RBI-regulated entities — user data is stored only in India, in line with RBI directives applicable to payment data.
9. What you should do
Security is a shared responsibility. On your side:
- Keep your WhatsApp two-step verification enabled and PIN private.
- If you lose your phone or number, contact us immediately at info@trenlytics.com so we can protect your HERE account.
- Do not share reminders or memory content that includes sensitive information (payment PINs, government IDs) unless you understand the risk of that information being retrievable later.
All security matters, including questions, disclosures and incident inquiries: info@trenlytics.com.