TellWang
Dashboard

Security & Compliance

TellWang is built for businesses that need to verify their security posture, not just assert it. Every guarantee on this page maps to a control you can audit against the live system.

Isolation (shipped)

Every Wok is private — its own Postgres container, its own services, on its own private network. Cross-tenant traffic is impossible at the network layer. At the API layer, every request that touches a Wok is authorized server-side against the owning team and returns a 404 — not a 403 — on cross-team access, so a foreign Wok's existence is never revealed. We re-verify this isolation automatically on every release: two Woks try to reach each other's realtime channels, and any cross-talk blocks the release. See Isolation tiers for the dedicated-host and confidential tiers on the roadmap.

Region

Today every Wok runs on a single region (ca-central-1, OVH Beauharnois). Multi-region failover and "pick the region your data lives in" are on the roadmap. If your compliance posture requires a specific region today, talk to the founders before provisioning.

Disaster recovery (shipped)

Backups are written daily to separate storage from your live data (MinIO bucket, off the Wok host). RPO is up to 24 hours today; continuous-WAL PITR is on the roadmap. The restore is verified, not just claimed — an ops-agent scheduled check recreates a random tenant on a scratch host every day and asserts data integrity. Failures land in the operator's incident journal before they can affect a customer restore.

Yours to audit & to take

Encryption & access (shipped)

Compliance

GDPR / CCPA data export and deletion of your live data are supported today; backup copies age out on their retention schedule afterward. SOC 2 is on the roadmap.

Roadmap