WITHMIA 5.0: the invisible release — a full security and quality audit
Twelve audit phases across every corner of the platform: isolation between companies, a payments layer verified against the source, hardened webhooks and data privacy. The release you can't see, but that holds everything up.
WITHMIA Team
WITHMIA
Some releases are announced with pretty screenshots, and then there are releases like this one: weeks on end without a single visible new feature. 5.0 was a deliberate decision — before stepping on the commercial accelerator, we put the entire platform through a full security and quality audit. If WITHMIA handles your conversations, your customers and your payments, we owed you that.
What we audited (everything)
We split the platform into twelve phases and went through them one by one: onboarding, communication channels, training and the knowledge base, payments and sales, scheduling and calendars, team and account management, CRM and portal, and the entire layer of internal services and jobs. Every endpoint, every permission, every data flow.
The method was adversarial: we didn’t ask “does it work?”, we asked “how does it break?” — with independent reviews that tried to refute each finding before it could be closed.
What this means for your business
Isolation between companies, reinforced. On a multi-company platform, the most important question is a boring one: can company A see anything belonging to company B? We reviewed every point where that could happen and closed even the most far-fetched scenarios — including secrets that are now derived from the tenant itself, impossible to impersonate from outside.
The money layer, verified against the source. Every amount charged is re-checked server-side with the payment provider — we never trust what arrives from the browser. Payment webhooks are idempotent: a duplicated retry does not create a duplicated charge. And the payment links your assistant generates are tied to the exact amount and product it quoted.
Hardened webhooks. All external inputs (WhatsApp, messaging, payments) require verified signatures or secrets. Anything unsigned doesn’t get in.
Privacy by default. We swept the system’s internal records so personal data and credentials aren’t written down even in diagnostic logs.
The number that matters to us
We closed the audit with a final verification of 132 checks across every corrected finding: zero open items. We’re not publishing this as a trophy — we’re publishing it as a commitment: security at WITHMIA is not a feature of the expensive plan, it’s the foundation of every plan, the Free one included.
Why we’re telling you
Because trust isn’t asked for, it’s demonstrated. The small businesses that use WITHMIA trust us with the most sensitive thing they have: their relationship with their customers and their sales flow. This invisible release is our way of taking that seriously — and the foundation for everything that came after it.
5.5 — the whole platform on your phone and an assistant that learns to sell — is already here. Read it on the blog.
Labels
Comments
Be respectful. Your email will not be published.