Wiggle BOS has not yet been independently audited or certified. This page says exactly what we do today to protect your data, and what comes next. We will update it as each step is completed.
Your data, always
- Your business data belongs to you. The workspace owner can export all of it at any time, in open formats, on every plan.
- We do not sell your information, and our AI model providers do not train their models on it.
- The Privacy Policy explains exactly what we collect, why, and how long we keep it.
How we protect it today
- Workspace isolation: each workspace's data is separated by rules inside the database itself. Automated tests check the isolation on every release, and the database rules are checked each time they change.
- Encryption: HTTPS everywhere in transit; encryption at rest by our database and storage providers; connection keys and mobile numbers are encrypted again by Wiggle.
- Roles and sign-in: role based access inside every workspace, two-step sign-in, and finance figures shown only to people given finance access.
- Staff access: Wiggle support opens a workspace only when its owner grants access, for the time and areas the owner chooses. Changes need a separate permission, and every visit is logged for the owner to see.
- Access log: a tamper-evident record of who viewed or changed what, including what Romey and connected apps read. Owners and admins can read it. It is kept 7 years for changes and 2 years for views.
- Connected apps and AI assistants: each one is listed in Settings and can be disconnected at any time, which ends its access immediately.
- Change control: every release runs Wiggle's full automated test suite and goes to a separate test copy before it reaches customers.
- Security reviews: we review the whole codebase for security and data protection issues, most recently in September 2026, and fixed every high-risk finding it found.
- Backups and uptime: our database provider takes daily backups, and we watch uptime around the clock on a public status page.
Service providers
The companies that process data for Wiggle, and what each one does, are listed in section 8 of the Privacy Policy. We update that list before adding a provider that handles workspace content.
What comes next
- Written security policies, mapped to the SOC 2 criteria (in progress)
- An independent penetration test
- An independent SOC 2 audit
- Point-in-time database recovery, before general launch
- Single sign-on (SAML and OIDC) and automatic user provisioning (SCIM) for larger teams
Documents and contacts
- Data processing agreement: being prepared. Email security@wigglebos.com to request it.
- Privacy Policy and Terms of Service
- Report a vulnerability: see our security and disclosure policy.
- Security questions: security@wigglebos.com