Trust
Trust, security and support.
You are trusting us with your customer conversations, so this page states plainly how your data is handled, which security practices are actually built and tested today, what we refuse to claim, and exactly how to reach a human. ConvoTide is at pilot stage — these statements describe the platform as it is built now, not aspirations.
Who operates ConvoTide
ConvoTide is built by Capricorncorp and operated by Moonshot AI Private Limited, the same entity that operates the sms-ocean messaging service. Your contractual relationship, invoices and support all point to one accountable company — not a maze of brands.
How your data is handled
- Consent is a record, not a checkbox. Consent is stored per contact, per channel and per purpose, with evidence. Campaign and journey sends are refused for contacts without opt-in on the channel being used — the refusal, not a warning, is the enforcement.
- Your contacts stay yours. You can export your contacts, and the export carries each contact’s per-channel consent state. Leaving with your data is a supported path, not an obstacle course.
- Cross-channel data is linked only with permission. Linking WhatsApp and SMS history for the same person happens only through an explicit, per-channel consent workflow — never a silent merge behind a shared login.
- Deletion on request. Requests to export or delete your business data go through the support routes below and are handled by a person who confirms the outcome.
- One honest boundary about WhatsApp itself. Message content on the WhatsApp Business Platform is processed by Meta under its own terms. We do not claim end-to-end India-only processing of message content, and any provider who claims a simple version of that is omitting how the platform works.
Platform security practices
These are practices built and tested in the running pilot service — each one observable in the product or its documented API:
- Least-privilege credentials. Sessions and API keys carry scopes, and a key can never exceed the permissions of the person who issued it. Actions outside your scope receive an explicit
SCOPE_DENIEDanswer, not silence. - Keys hashed at rest. API keys are shown once at issue and stored only as hashes — a database copy is not a usable key ring.
- Signed webhooks, verified before storage. Provider webhook signatures are verified over the exact raw bytes before anything is persisted, and the raw event is stored before it is acknowledged — so delivery records can be replayed and audited.
- Row-level access in the database. Tenant isolation is enforced at the database layer with row-level security and verified by automated tests against a real database — not only by application code that could be bypassed.
- Analytics that carry no identities. Product analytics events exclude message content, phone numbers, tokens and contact identifiers.
- Human control over automation. Any automated or AI-drafted conversation can be taken over by a person, and campaigns can be paused in seconds by a named human.
What we will and won’t claim
Equally: pilot-stage does not mean careless. The practices listed above exist because customer data deserves them from the first tenant, not after a funding round. Where a control is still being hardened, the pilot agreement says so in writing instead of this page implying completeness.
Status and change log
The workspace includes a trust panel that reads the platform’s public status and change-log endpoints. It follows one rule: if the status service cannot confirm health, the page shows an error — it never renders a green “all systems operational” banner it cannot back. The change log lists what actually changed, newest first, served by the platform itself.
Support and escalation
- During the pilot, customers work directly with the founding team through onboarding and first campaigns; the exact support window is agreed in your pilot proposal. Start with the demo request form.
- Data protection and grievances. The operating entity’s privacy policy — including its named Grievance Officer and data-deletion process — is published at capricorncorp.com/privacy-policy.
- ConvoTide-specific terms are published before paid general availability; until then pilot terms are provided with the pilot proposal rather than implied by this site.
- Technical questions about the API are answered from the developer documentation — which documents the real surface, including its refusals.
Content reviewed October 2026 · owner: Zcode (implementation) · independent factual review: Codex QC, pending.