Last updated: June 2026

Security

Security is foundational to Barrq. We handle messaging and commerce data for businesses and their customers, and we design the platform to protect that data at every layer.

Encryption

Data is encrypted in transit using TLS. Sensitive data is encrypted at rest, and integration secrets and access tokens are encrypted with AES-256-GCM before storage.

Tenant isolation

Barrq is multi-tenant by design. Every database query is scoped to a single company through a centralized data-access layer, so one brand can never read or write another brand’s data. Cross-tenant access by operators is restricted and audited.

Access controls

  • Least-privilege access for our team, with administrative actions written to an immutable audit log.
  • Scoped, signed sessions for tenant and admin users.
  • Role-based permissions within your workspace.

Application security

  • Input validation and output encoding across the platform.
  • Dependency and vulnerability monitoring.
  • Secure software-development practices and code review.

Monitoring & logging

Integration activity and administrative actions are logged to support monitoring, troubleshooting, and incident response.

Resilience & backups

We use managed, redundant infrastructure and maintain backups to support recovery in the event of failure.

Platform compliance

We operate within WhatsApp, and Meta platform policies and use official APIs for messaging.

Responsible disclosure

If you believe you have found a security vulnerability, please report it to security@barrq.co. We appreciate responsible disclosure and will investigate all legitimate reports.

Your responsibilities

Help keep your workspace secure: use a strong, unique password, protect your credentials, and grant access only to people who need it.