WITHMIA v1.2.0 — Enterprise-grade security for your conversations
We invested heavily in hardening the platform: credentials encrypted at rest, payments with TLS verification and authenticated webhooks, defenses against web attacks (SSRF, XSS, clickjacking), a full rotation of secrets, an anti-bot captcha and validation of real phone numbers by country, plus a comprehensive security audit with adversarial verification. Your business and your customers, better protected.
WITHMIA Team
WITHMIA
When a company trusts WITHMIA to talk to its customers, it hands us something very valuable: its data and its people’s data. v1.2.0 is our most important release on that front. We ran a comprehensive security audit of the entire platform and reinforced every layer, from the database to the browser.
This isn’t a single feature. It’s a cross-cutting investment in trust.
A serious audit, not a checklist
We reviewed the whole platform against the attack surfaces that matter in a multi-tenant SaaS: access control between companies, authentication, injection, XSS, SSRF, webhooks, secrets, headers, rate limits, dependencies and infrastructure.
Every finding went through an adversarial verification: before accepting anything as true, we tried to refute it, so we wouldn’t burn time on false positives and would only fix what actually matters. What we confirmed, we fixed. What was critical, we fixed first.
What we reinforced
🔐 Credentials encrypted at rest. Sensitive integration credentials are stored encrypted in the database, not in plain text. If something ever leaked, it’s useless without the key.
💳 Payments hardened. We restored TLS certificate verification along the entire payment path and made billing webhooks forgery-proof: every payment notification is validated against the authoritative source before any subscription is activated. Nobody activates a plan they didn’t pay for.
🛡️ Defenses against web attacks. Reinforced protection against SSRF (forced server-side requests), stored XSS (rejecting dangerous uploads such as SVG) and clickjacking. We added modern security headers (X-Frame-Options, Referrer-Policy, HSTS) to every response.
🔑 A full rotation of secrets. We rotated the platform’s internal keys and passwords and verified service by service that everything kept working, with no interruption to your operation.
🚦 Limits and traceability. We tuned the rate limits on sensitive endpoints to curb automated abuse, and started recording access metadata to spot suspicious patterns early.
🧹 Privacy hygiene. We stopped writing personal data (messages, phone numbers) into logs and removed any echo of sensitive information from error responses.
Real people only
A secure platform also means that there are people on the other side, not bots. In this release we added two defenses at sign-up:
🤖 An invisible anti-bot captcha. We integrated a modern captcha (Cloudflare Turnstile) at login. It stops automated bot registration without bothering real people — most never notice it.
📞 Real phone numbers, by country. We now validate every phone number against its country’s actual numbering plan (using Google’s libphonenumber). A made-up number with the right length no longer gets through: if it doesn’t exist, it’s rejected. Cleaner data for you and one more barrier against fake sign-ups — in Chile, Argentina, Peru or wherever your customers are.
Transparency and security at once
Security isn’t about hiding how the platform works; it’s about every layer holding up on its own. In this release we hardened the configuration of the entire infrastructure: internal services that aren’t exposed to the network, and mandatory authentication on every component.
What’s next
Security isn’t a destination, it’s a habit. We’re already working on the next layer: a redesign of session handling (encrypted tokens with expiry), continuous dependency updates and even stricter content policies in the browser. We’ll be shipping these over the coming releases.
If you run a company and the security of your data is a priority — as it should be — v1.2.0 is a good reason to try WITHMIA with peace of mind.
Questions about how we protect your data? Write to us. We’ll gladly walk you through the details.
Labels
Comments
Be respectful. Your email will not be published.