Compliance & trust
A single gateway enforces authentication, scope, entitlement, and metering for every WAVE product. That one enforcement plane is also where the documented compliance posture lives.
- Privacy: GDPR & CCPA aligned, with a signed DPA available.
- Healthcare: HIPAA-ready under a signed Business Associate Agreement (BAA).
- AI transparency: EU AI Act Article 26 record-keeping, with immutable audit records and multi-year retention.
- Messaging: A2P 10DLC compliant.
- Infrastructure: built on Cloudflare, Supabase, and Stripe — all SOC 2 Type II infrastructure.
WAVE itself does not hold a SOC 2 or ISO attestation. What's below is the contract every call runs through, and it's public:
curl -s https://api.wave.online/openapi.json | jq '.info'
Every request path, scope, and error shape in that contract is what the gateway actually enforces — see Errors for the normalized error envelope every failure returns.
Full detail and every legal document live at wave.online/trust.