Home · Security and compliance
Security and compliance
Operations across Europe, data in Switzerland
For regulated industries and companies that take data residency seriously, this isn't a marketing line: it's a condition of entry. Sandra has been built that way since day one.
Our guarantees

Hosted in Switzerland, at Infomaniak
Application data is stored and processed at Infomaniak, in Switzerland. No replication outside the country for the data we control.

Direct access to the WhatsApp API
Priority support from Meta and early access to new WhatsApp Business API features.


FADP and GDPR built in
Opt-in collection and time-stamping, right to erasure, processing register and retention policy built in, not bolted on afterwards.
Access control and audit
Granular roles by channel and by team, authentication, and an exportable audit log of every action.
What stays with us, what goes through Meta
We'd rather be precise than reassuring. Sandra runs on the official WhatsApp Business API: messages necessarily travel through Meta's infrastructure, as they do for any lawful WhatsApp solution. What sets us apart is what we do with everything else.
- Hosted and processed in Switzerland: your contacts, conversation history, scenarios, segments, analytics data and AI agent configurations.
- Travelling through Meta: the routing of the messages themselves, under the WhatsApp Business API terms.
- Processed by the model providers: the content submitted to the AI agents, according to the model chosen for each use case. We document that choice, and we can favour a European model when sensitivity calls for it.
If a vendor tells you nothing goes through Meta, they are either not telling the truth or not using the official API. Both should worry you.
Security questionnaires
The Growth and Enterprise plans include support in completing your vendor security questionnaires. We maintain an up-to-date pack covering the architecture, the sub-processors, data location and incident procedures.
A compliance question before going further?
We answer in writing, with the technical detail your DPO or CISO expects.
