Trust

Security and privacy at Waffle

Waffle is built on least privilege, encrypted secrets, and admin control over the AI and your connectors, with a cookieless marketing site.

Last updated July 2026

How we think about it

Waffle follows least privilege. Sensitive secrets such as connector tokens are encrypted at rest, access is role based, and uploaded files are served only through membership checked routes. Admins control Waffle AI per channel and scope which tools it may use. The marketing site is cookieless, with no third party trackers.

Least privilege matters because access is where most incidents start. Stolen or compromised credentials were the single most common initial attack vector in 2024, and those breaches took the longest to detect and contain, at nearly ten months on average IBM Cost of a Data Breach Report, 2024. That is why Waffle keeps secrets encrypted, scopes what the AI can reach, and never shows a connector token again after setup.

We aim for defaults that are safe on their own and controls that are easy to reason about. Where a capability could reach outside your team, such as an AI connector or a pull request, an admin decides and a human stays in the loop. As of 2026 Waffle does not hold a formal SOC 2 or ISO certification, and we do not claim one.

Protecting your connections

A connector token is a live key into another system, and over the past decade the use of stolen credentials has appeared in almost a third of all breaches Verizon Data Breach Investigations Report, 2024. So Waffle encrypts connector tokens at rest with AES-256-GCM and never shows them again after setup. Admins scope which connectors each channel may use, and set each connector to read only or read and write. When Waffle AI opens a pull request, it lands as a draft that an admin must approve before it can merge.

  • Connector tokens are encrypted at rest with AES-256-GCM and never returned by an API or shown again after setup.
  • Admins scope which connectors each channel may use: all, none, or a hand picked set.
  • Each connector is set to read only, or read and write, per connector.
  • The AI opens pull requests only as drafts, which cannot merge until an admin approves them.
  • Anything a connected tool returns is treated as untrusted input, never as instructions.

Access and administration

Access in Waffle is role based. Owners and admins hold granular permissions, private channels are limited to their members, and uploaded files are served only through membership checked, id fenced routes. Accounts support password reset and email verification, so control of an inbox controls the account.

  • Owner and admin roles with granular permissions.
  • Private channels, visible only to the members who belong to them.
  • Uploads served only through membership checked, id fenced routes, with no public static file mounts.
  • Password reset and email verification for accounts.

Privacy on this website

This marketing site uses first party, cookieless analytics. There are no third party trackers and no consent banner is required. It sets no cookie and stores no cross day identifier. Raw IP and user agent are used transiently at ingest, then discarded. Only aggregate rows are ever stored.

At ingest, the raw IP is used only for coarse geography, and the raw IP and user agent together seed a daily rotating visitor hash so we can count unique visits without identifying anyone. Both are discarded immediately after and are never stored or logged. The result is honest, aggregate measurement that keeps our promise of no third party trackers and no consent banner. The full details are in our privacy policy.

Company

Waffle is built by Friskly AB, a company based in Sweden. If you have a security question, or you would like to report something you believe is a vulnerability, please reach us through our contact page and we will follow up.

Frequently asked questions

Is Waffle secure?
Waffle is built on least privilege and admin control. Sensitive secrets such as connector tokens are encrypted at rest with AES-256-GCM and never shown again. Access is role based, uploads are served only through membership checked routes, and Waffle AI is scoped per channel. As of 2026 Waffle does not hold a formal SOC 2 or ISO certification, and we do not claim one.
How are my connector tokens stored?
When you connect a tool like GitHub, Linear, or a custom MCP server, its token is encrypted at rest with AES-256-GCM before it is written to the database. Tokens are never returned by any API and never logged. After you save a connector, the token is not shown again. Decryption fails closed if anything is wrong.
Does Waffle track me with cookies?
The Waffle marketing site uses first party, cookieless analytics with no third party trackers, so no consent banner is required. It sets no cookie and stores no cross day identifier. Raw IP and user agent are used transiently at ingest for coarse geography and a daily rotating visitor hash, then discarded. Only aggregate rows are stored.
Can admins control what the AI can do?
Yes. Owners and admins turn Waffle AI on or off per channel and can give it a per channel persona. Admins choose which connectors each channel may use and set each connector to read only or read and write. When the AI opens a pull request it lands as a draft that an admin must approve before it can merge.
Who can see my messages?
Messages live inside your team and follow its membership and roles. Public channels are visible to members of your team, and private channels only to their members. Direct messages are between their participants. Uploaded files are served only through membership checked, id fenced routes, so there are no public file links to your content.

Sources

Statistics on this page are drawn from independent, named security research. Figures are quoted as reported by their sources.

Give your team its extra member.

Waffle is in early access. Creating a team takes about two minutes, and Waffle AI is ready the moment you do.