Technical Overview

How ChatFox is built,
integrated and governed.

A deeper look for technical, IT and operational stakeholders — covering architecture, data handling, integrations and the controls that keep it production-safe.

If you are primarily interested in business outcomes, pricing or use cases, you do not need to read this page.
// End-to-end flow

What happens in a single message

ChatFox operates on WhatsApp via the official WhatsApp Business API. It connects securely to your systems, orchestrates the AI response and returns a validated reply — typically in seconds. Here is the full path of one interaction.

03

ChatFox processes and applies context

ChatFox establishes context and applies your configured controls before anything else happens:

  • Conversation context is loaded, including history where enabled
  • Agent prompts, business rules and safety policies are applied
  • Relevant data can be retrieved from connected systems
3a · Optional integrations

ChatFox can read from or write to CRM platforms, accounting systems, calendars, email and custom back-office systems via API.

04

The AI model generates a response

Relevant message content and context is sent to your selected LLM provider — or a self-hosted model — which generates a response based on your prompts, rules and available context.

05

ChatFox validates and enhances it

Before anything is delivered:

  • Safety filters and validation rules are applied
  • Configured tool actions run — create a lead, update a record, book an appointment
  • Formatting is applied for WhatsApp, and audit logs and state are updated
// Architecture & governance

The detail, by topic

ChatFox is a fully managed solution — not a self-service builder. Configuration, integration, deployment and ongoing management are handled by the ChatFox team to ensure stability, security and real-world usability.

WhatsApp integration

ChatFox connects using the official Meta WhatsApp Business API, for a secure and compliant implementation.

  • You retain full ownership and control of your Meta and WhatsApp Business accounts
  • ChatFox can assist with WhatsApp Business Account (WABA) setup if required
  • ChatFox is added as a partner to your WABA — integration access without transferring ownership
  • Messages are sent and received via the official Meta API, with secure webhooks delivering incoming messages in real time

ChatFox never takes ownership of your accounts or customer data. Access can be revoked at any time.

AI models & provider flexibility

ChatFox is provider-agnostic and can operate with a wide range of LLM providers:

OpenAI (GPT-5 / 4 / 3.5)
Google Gemini
Anthropic Claude
Azure OpenAI
Mistral & open-source
Self-hosted models

Different agents or use cases can run on different models — optimising for performance, cost or compliance. You are not locked into a single AI provider.

You contract with and pay your AI provider directly. ChatFox does not resell or bundle AI usage. If a provider changes pricing, rate limits or policies:

  • The change is handled between you and the provider
  • ChatFox continues to operate independently
  • The team can support reconfiguration, optimisation or switching providers if required
Data, hosting & ownership

ChatFox's services and all data retained by ChatFox are securely hosted in the United Kingdom, using AWS Europe (London) · eu-west-2.

  • Data retained by ChatFox stays within UK data centres
  • ChatFox does not move or store retained data outside the UK

Two things to note: WhatsApp messages are processed through Meta's global infrastructure and may be handled outside the UK; and AI processing is performed by your selected LLM provider, so depending on the provider, data sent for inference may temporarily leave the UK.

ChatFox platform processing — messages are processed to operate the service, manage conversation flows, store history where enabled, and support analytics and hand-off.

AI model processing — when AI responses are required, relevant data is sent to your selected LLM provider. Cloud models process under the provider's policies; self-hosted models keep all processing within your own infrastructure.

ChatFox does not sell or share client data.

Yes — and storage is fully configurable by you. You control whether conversation data is stored and how long it is retained. History can improve contextual accuracy but can be limited or disabled to meet internal or regulatory requirements.

All client data can be exported via the ChatFox admin interface — custom prompts, conversation histories, WhatsApp user details and other chatbot data. You retain full ownership. Nothing is locked in.

Integrations & automation

Yes — ChatFox can read and write to third-party and external systems, enabling real business process automation:

  • CRM platforms — Salesforce, HubSpot, Zoho
  • Accounting — QuickBooks, Xero, Sage
  • Microsoft 365 — email, calendars, contacts
  • Google Workspace — Calendar, Sheets, email
  • Custom or proprietary systems via API

Integrations are scoped and configured during setup based on your requirements.

Yes — ChatFox supports seamless AI-to-human hand-off:

  • Manual takeover via the admin interface
  • Automated alerts when defined conditions are met
  • Pausing AI responses during human interaction
  • Returning control to the AI when appropriate

Automation stays balanced with human oversight.

Reliability, monitoring & access

ChatFox aims to deliver high service uptime in line with industry standards for SaaS platforms. Systems run on robust infrastructure with multiple safeguards and are monitored 24/7. Planned maintenance or incidents are communicated where possible.

Occasional interruptions may occur due to factors outside ChatFox's control, such as third-party outages, but reliability is treated as a priority. Support response times are governed by ChatFox's internal support SLA, which can be discussed directly with the team.

ChatFox uses a combination of custom-built monitoring and industry-standard infrastructure monitoring:

  • 24/7 monitoring and real-time alerting
  • Detailed logging of system health and message flows
  • Monitoring of message delivery and processing performance

Where appropriate, monitoring data and logs can be made available to clients. If issues are detected, the team is alerted immediately.

Access to the admin portal uses One-Time Passwords (OTP) sent to the registered email address:

  • No passwords to manage or remember
  • OTPs are single-use and time-limited
  • Access requires both email ownership and the active OTP

Additional access control requirements can be discussed.

Safety, security & compliance

ChatFox follows established security best practices and is actively working towards certification for:

  • ISO 27001 — Information Security Management
  • ISO 42001 — AI Management Systems

Controls include independent penetration testing, regular system reviews and industry-standard data protection practices.

ChatFox implements its own safety, audit and validation layers, in addition to safeguards from the AI model providers:

  • Configurable safety filters
  • Pre-processing validation before data reaches an LLM
  • Post-processing validation before responses are sent
  • Comprehensive audit logging
  • Policy-driven configuration aligned with regulatory or internal requirements

A layered approach that ensures control, traceability and compliance.

// At a glance

Summary for technical stakeholders

Official WhatsApp Business API integration

Provider-agnostic AI model architecture

UK-hosted platform data (AWS London)

Client-controlled data retention and export

Layered safety, audit and validation controls

Third-party system integration (read / write)

Human hand-off and managed support

Continuous monitoring and reliability focus

Questions we haven't answered?

Bring your architecture, security or compliance requirements to a technical discovery call — or ask Basil directly.

Ask Basil on WhatsApp
Ask Basil on web chat!