Your Security Is Our Priority
At Whatfix, protecting the confidentiality, integrity, and availability of customer data is central to the design and operation of our DAP services. Security and privacy are embedded throughout the SaaS lifecycle, from development through ongoing operations.
Our program is supported by industry-recognized frameworks, strong technical and organizational controls, and continuous monitoring to safeguard data against unauthorized access, disclosure, alteration, and loss. We operate under a shared responsibility model and support our customers in meeting applicable regulatory and data protection requirements.
This Trust Center provides transparency into our security, privacy, and compliance practices, including relevant policies, certifications, and documentation.
**Note: All documents, materials, and information accessed through this Trust Center are Confidential and subject to the terms of your Non-Disclosure Agreement (NDA) with Whatfix. By accessing this content, you agree to handle all information responsibly and not disclose it to unauthorized parties.*
Founded in 2014
Read the most recent and major updates about Whatfix’s security program.
Security Advisory: Axios npm Supply Chain Attack (March 2026)
Apr 1, 2026
Date: April 1, 2026
Severity: Informational - No Impact to Whatfix
Category: Third-Party Supply Chain
Overview
On March 30-31, 2026, threat actors hijacked the npm account of an axios maintainer and published two malicious versions - axios@1.14.1 and axios@0.30.4 - bundling a phantom dependency (plain-crypto-js@4.2.1) that dropped WAVESHAPER.V2, a cross-platform remote access trojan (RAT). The packages were live for approximately 2-3 hours before removal. Attribution: UNC1069 (North Korea-nexus, Google GTIG).
Whatfix is not impacted.
Why Whatfix Was Not Affected
Dependency Locking: All Whatfix Node.js projects use lockfiles (package-lock.json / yarn.lock) that pin exact versions and integrity hashes. Lockfiles referenced safe versions, so the malicious releases were never resolved.
JFrog Artifactory: All npm resolution is routed through Whatfix's internal JFrog Artifactory instance, not directly to the public npm registry. The malicious packages were never requested through or cached in Artifactory during the exposure window.
IOC Verification
Whatfix's AppSec team confirmed no indicators of compromise across CI/CD pipelines, developer machines, and Artifactory logs:
Status: No action required. Whatfix systems and customer data are not affected.
Reference: StepSecurity technical blog - https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan
Whatfix SOC 2 Type 2
Feb 23, 2026