Skip to main content

Security & Privacy

Volxim is a managed WhatsApp automation service. This page describes how this website (volxim.com) is actually configured today. It is a factual description of the current setup, not a set of promises about outcomes.

What this site does and does not do

This page describes the current website and service process. It does not create accounts or process payments. The business fit check, Contact form, and Onboarding form send and store your details only after you check the consent box and submit, solely to handle your inquiry or onboarding request. The Hebrew scoping tool at /start and the partners tool remain browser-only. See our Privacy Policy for full details and the deletion path. A live WhatsApp Business connection happens only after scoping, a fit check, an approved proposal, and verified payment.

How the site is served

  • The site is served over HTTPS.
  • TLS 1.3 is supported for the connection between your browser and the site.
  • HSTS is enabled, so browsers are told to use HTTPS on future visits.
  • The /start fit check runs entirely in your browser; your answers are not sent to a server unless you choose to share the resulting summary yourself.

Browser hardening (response headers)

  • X-Frame-Options: DENY, so the site is not embedded inside another page's frame.
  • X-Content-Type-Options: nosniff, so browsers do not second-guess declared content types.
  • A Referrer-Policy that limits what is shared when you follow an outbound link.
  • A Permissions-Policy that restricts access to sensitive browser features.

Data and tracking

  • No tracking cookies are set by this site.
  • No Google Analytics, Google Tag Manager, or Meta pixel is loaded.
  • No secrets or API keys are present in the client-side code.
  • The public site is a static export, with no admin or login area exposed on it.
  • Directory listing is turned off.
  • Access to any stored inquiry, lead, or onboarding data is limited to authorized Volxim personnel and systems.

Reporting

If you find a security or privacy issue, please email support@volxim.com and we will look into it.

Working model and third-party dependencies

Volxim works as an integrator on top of established platforms such as the WhatsApp Business API through Meta. A live connection also depends on Meta and third-party providers, including an API provider (BSP), a CRM, and Cloudflare, which are outside Volxim's control and are governed by their own policies and approvals.

Shared responsibility

Security is shared. Volxim configures and connects your automation on established platforms; the live WhatsApp connection, message delivery, and data processing also depend on Meta, an API provider (BSP), your CRM, and Cloudflare, each governed by its own security and policies. You are responsible for your own account credentials and your obligations to your customers.

What we do not claim

We do not claim formal third-party security certifications, a formal service-level commitment, independent security-testing attestation, or that the site or service offers absolute security. No system can be completely secure; this page describes what is actually configured, not a set of promises.

Known limitations and documents

This is a product-preview website, and some areas are still being built. For how we handle personal data, see our Privacy Policy; for terms, see our Terms of Service.