Certifications and Compliance
SOC 2 Type II
Soneka is audited annually against the AICPA Trust Services Criteria covering security, availability, and confidentiality. Our most recent report is available to Enterprise customers under NDA.
ISO 27001
Our information security management system (ISMS) is certified to ISO/IEC 27001, demonstrating systematic controls over how data is managed, stored, and protected.
GDPR
Soneka is fully compliant with the Kenya and EU General Data Protection Regulation. We act as a data processor under your instructions and provide a Data Processing Agreement (DPA) to all customers on request.
HIPAA-Eligible
Soneka’s infrastructure supports HIPAA-eligible workloads. Healthcare customers on Enterprise can request a Business Associate Agreement (BAA) from their account manager.
To request a copy of our SOC 2 report, ISO certificate, standard DPA, or BAA, email legal@soneka.africa with your workspace name and company details.
Data Residency
By default, Soneka stores data in our primary region. Enterprise customers can choose a dedicated data residency region to satisfy local data sovereignty requirements:
Data residency means your workspace data — contacts, messages, templates, and logs — is written to and stored exclusively within the selected region. To configure data residency, raise a request with your account manager before your workspace is provisioned; region selection cannot be changed after setup.
Encryption
All data in Soneka is encrypted both in transit and at rest.- In transit: All connections between your browser, Soneka’s APIs, and our infrastructure use TLS 1.3. Older protocol versions (TLS 1.0, 1.1) are rejected.
- At rest: All stored data — databases, backups, file attachments — is encrypted using AES-256. Encryption keys are managed via a dedicated key management service with automatic rotation.
Two-Factor Authentication (2FA)
Enabling 2FA on your account is strongly recommended and takes less than two minutes.1
Open Security Settings
Go to your Profile → Security → Two-Factor Authentication.
2
Choose Your Method
Select either an authenticator app (Google Authenticator, Authy, 1Password, etc.) or SMS as your second factor. Authenticator apps are more secure and recommended.
3
Scan the QR Code
If using an authenticator app, scan the QR code displayed on screen. Enter the 6-digit code from your app to confirm the pairing.
4
Save Your Backup Codes
Soneka will display 8 one-time backup codes. Store these somewhere safe (a password manager is ideal). These codes let you access your account if you lose your second-factor device.
IP Allowlist
Restrict Soneka workspace access to specific IP addresses or CIDR ranges. When an allowlist is active, login attempts from any IP not on the list are blocked — even with valid credentials and a valid 2FA code. To configure the allowlist:- Go to Admin → Settings → Security → IP Allowlist.
- Add the IP addresses or CIDR ranges your team uses (e.g., your office IP, VPN exit nodes).
- Click Save and Enable.
Audit Logs
Every action taken inside your Soneka workspace is recorded in the audit log: logins, contact edits, flow changes, broadcast launches, permission changes, API key creation, and more.
To access audit logs, go to Admin → Settings → Audit Log. Logs can be filtered by user, date range, and action type, and exported as CSV or JSON.
Webhook Signatures
Every webhook event dispatched by Soneka includes anX-Soneka-Signature header containing an HMAC-SHA256 signature of the request body. Verifying this signature ensures the request genuinely originated from Soneka and has not been tampered with in transit.
WhatsApp Guardrails
Soneka includes built-in filters to protect your WhatsApp Business Account quality rating and keep your workspace compliant with Meta’s messaging policies:- Scam and abuse filters scan outbound message content and flag patterns associated with phishing, financial fraud, and prohibited content categories before messages are sent.
- Quality score monitoring alerts you when your phone number’s Meta quality rating drops below a healthy threshold, giving you time to address opt-out spikes before a number gets flagged or banned.
- Opt-out enforcement automatically removes contacts who reply with standard opt-out keywords (STOP, UNSUBSCRIBE, etc.) from future broadcasts.
Data Deletion
You have three ways to permanently delete your workspace data:Delete via Facebook App Permissions
Delete via Facebook App Permissions
Go to your Facebook Business Settings → Business Integrations and revoke Soneka’s app permissions. This immediately destroys all active API tokens and triggers the data deletion pipeline.
Delete via Email Request
Delete via Email Request
Email support@soneka.africa with the subject line “Data Deletion Request” and include your workspace name and the email address associated with your account. Our team will confirm the request within one business day.
Delete via Workspace Settings
Delete via Workspace Settings
Go to Admin → Settings → Account Profile → Delete Account & Workspace. You will be asked to type your workspace name to confirm. This action is irreversible.
- Active API tokens are destroyed instantly upon deletion request.
- Active database records are wiped within 30 business days.
- Encrypted backups are rotated and purged within 60 business days.