Media

Money

Dispatch

Company

Compliance & trust

A single gateway enforces authentication, scope, entitlement, and metering for every WAVE product. That one enforcement plane is also where the documented compliance posture lives.

  • Privacy: GDPR & CCPA aligned, with a signed DPA available.
  • Healthcare: HIPAA-ready under a signed Business Associate Agreement (BAA).
  • AI transparency: EU AI Act Article 26 record-keeping, with immutable audit records and multi-year retention.
  • Messaging: A2P 10DLC compliant.
  • Infrastructure: built on Cloudflare, Supabase, and Stripe — all SOC 2 Type II infrastructure.

WAVE itself does not hold a SOC 2 or ISO attestation. What's below is the contract every call runs through, and it's public:

curl -s https://api.wave.online/openapi.json | jq '.info'

Every request path, scope, and error shape in that contract is what the gateway actually enforces — see Errors for the normalized error envelope every failure returns.

Full detail and every legal document live at wave.online/trust.