How ChatFox is built,
integrated and governed.
A deeper look for technical, IT and operational stakeholders — covering architecture, data handling, integrations and the controls that keep it production-safe.
What happens in a single message
ChatFox operates on WhatsApp via the official WhatsApp Business API. It connects securely to your systems, orchestrates the AI response and returns a validated reply — typically in seconds. Here is the full path of one interaction.
Customer sends a message
A user messages you on WhatsApp using the standard app — no downloads, no accounts, available 24/7.
WhatsApp Business API receives it
The message arrives through Meta's official WhatsApp Business API, and a secure webhook notifies ChatFox in real time.
ChatFox processes and applies context
ChatFox establishes context and applies your configured controls before anything else happens:
- Conversation context is loaded, including history where enabled
- Agent prompts, business rules and safety policies are applied
- Relevant data can be retrieved from connected systems
ChatFox can read from or write to CRM platforms, accounting systems, calendars, email and custom back-office systems via API.
The AI model generates a response
Relevant message content and context is sent to your selected LLM provider — or a self-hosted model — which generates a response based on your prompts, rules and available context.
ChatFox validates and enhances it
Before anything is delivered:
- Safety filters and validation rules are applied
- Configured tool actions run — create a lead, update a record, book an appointment
- Formatting is applied for WhatsApp, and audit logs and state are updated
Response delivered via WhatsApp
ChatFox sends the validated reply back through the WhatsApp Business API, delivered via Meta's infrastructure.
Customer receives the reply
The user gets an immediate response in the same conversation, which continues seamlessly with optional history retained for future context.
The detail, by topic
ChatFox is a fully managed solution — not a self-service builder. Configuration, integration, deployment and ongoing management are handled by the ChatFox team to ensure stability, security and real-world usability.
ChatFox connects using the official Meta WhatsApp Business API, for a secure and compliant implementation.
- You retain full ownership and control of your Meta and WhatsApp Business accounts
- ChatFox can assist with WhatsApp Business Account (WABA) setup if required
- ChatFox is added as a partner to your WABA — integration access without transferring ownership
- Messages are sent and received via the official Meta API, with secure webhooks delivering incoming messages in real time
ChatFox never takes ownership of your accounts or customer data. Access can be revoked at any time.
ChatFox is provider-agnostic and can operate with a wide range of LLM providers:
Different agents or use cases can run on different models — optimising for performance, cost or compliance. You are not locked into a single AI provider.
You contract with and pay your AI provider directly. ChatFox does not resell or bundle AI usage. If a provider changes pricing, rate limits or policies:
- The change is handled between you and the provider
- ChatFox continues to operate independently
- The team can support reconfiguration, optimisation or switching providers if required
ChatFox's services and all data retained by ChatFox are securely hosted in the United Kingdom, using AWS Europe (London) · eu-west-2.
- Data retained by ChatFox stays within UK data centres
- ChatFox does not move or store retained data outside the UK
Two things to note: WhatsApp messages are processed through Meta's global infrastructure and may be handled outside the UK; and AI processing is performed by your selected LLM provider, so depending on the provider, data sent for inference may temporarily leave the UK.
ChatFox platform processing — messages are processed to operate the service, manage conversation flows, store history where enabled, and support analytics and hand-off.
AI model processing — when AI responses are required, relevant data is sent to your selected LLM provider. Cloud models process under the provider's policies; self-hosted models keep all processing within your own infrastructure.
ChatFox does not sell or share client data.
Yes — and storage is fully configurable by you. You control whether conversation data is stored and how long it is retained. History can improve contextual accuracy but can be limited or disabled to meet internal or regulatory requirements.
All client data can be exported via the ChatFox admin interface — custom prompts, conversation histories, WhatsApp user details and other chatbot data. You retain full ownership. Nothing is locked in.
Yes — ChatFox can read and write to third-party and external systems, enabling real business process automation:
- CRM platforms — Salesforce, HubSpot, Zoho
- Accounting — QuickBooks, Xero, Sage
- Microsoft 365 — email, calendars, contacts
- Google Workspace — Calendar, Sheets, email
- Custom or proprietary systems via API
Integrations are scoped and configured during setup based on your requirements.
Yes — ChatFox supports seamless AI-to-human hand-off:
- Manual takeover via the admin interface
- Automated alerts when defined conditions are met
- Pausing AI responses during human interaction
- Returning control to the AI when appropriate
Automation stays balanced with human oversight.
ChatFox aims to deliver high service uptime in line with industry standards for SaaS platforms. Systems run on robust infrastructure with multiple safeguards and are monitored 24/7. Planned maintenance or incidents are communicated where possible.
Occasional interruptions may occur due to factors outside ChatFox's control, such as third-party outages, but reliability is treated as a priority. Support response times are governed by ChatFox's internal support SLA, which can be discussed directly with the team.
ChatFox uses a combination of custom-built monitoring and industry-standard infrastructure monitoring:
- 24/7 monitoring and real-time alerting
- Detailed logging of system health and message flows
- Monitoring of message delivery and processing performance
Where appropriate, monitoring data and logs can be made available to clients. If issues are detected, the team is alerted immediately.
Access to the admin portal uses One-Time Passwords (OTP) sent to the registered email address:
- No passwords to manage or remember
- OTPs are single-use and time-limited
- Access requires both email ownership and the active OTP
Additional access control requirements can be discussed.
ChatFox follows established security best practices and is actively working towards certification for:
- ISO 27001 — Information Security Management
- ISO 42001 — AI Management Systems
Controls include independent penetration testing, regular system reviews and industry-standard data protection practices.
ChatFox implements its own safety, audit and validation layers, in addition to safeguards from the AI model providers:
- Configurable safety filters
- Pre-processing validation before data reaches an LLM
- Post-processing validation before responses are sent
- Comprehensive audit logging
- Policy-driven configuration aligned with regulatory or internal requirements
A layered approach that ensures control, traceability and compliance.
Summary for technical stakeholders
Official WhatsApp Business API integration
Provider-agnostic AI model architecture
UK-hosted platform data (AWS London)
Client-controlled data retention and export
Layered safety, audit and validation controls
Third-party system integration (read / write)
Human hand-off and managed support
Continuous monitoring and reliability focus
Questions we haven't answered?
Bring your architecture, security or compliance requirements to a technical discovery call — or ask Basil directly.
Ask Basil on WhatsApp