Your recordkeeping obligations apply to the content of the business conversation, not the channel it traveled through. If your team is doing business on WeCom or WeChat, those messages are business records — and your firm is responsible for retaining and producing them on demand.
We all watched this play out in the 2021–2024 off-channel sweep. The activity was happening in WhatsApp, Signal, and iMessage, but the firms hadn’t captured it, and the penalties followed. WeCom creates the same gap. The regulated firms that think they need WeChat capture almost always need WeCom.
Most archiving solutions either skip WeCom entirely or route capture through a third-party relay with per-user credential handshakes. Comma reads WeCom’s server-side archive API directly — no relay, no device agent, no per-employee OAuth setup.
What Comma captures from WeCom
Comma captures 1:1 and group enterprise chats, file and image attachments, reactions and edits where the WeCom API exposes them, external consumer-WeChat messages routed through WeCom’s external contacts feature, and full metadata: sender, timestamps, and conversation context. All of it lands in the same tamper-protected archive as your other channels, with a single supervision queue.
How the WeCom integration works
Comma pulls WeCom conversations straight from WeCom’s server-side archive API. No third-party relay, no agent on anyone’s device, no per-user OAuth handshake.
Why the architecture matters
For your compliance team
One archive, one review queue
WeCom activity lands alongside your other 40+ channels. One supervision workflow covers everything, so compliance teams do not need a separate tool for WeChat.
Complete metadata
Sender, timestamps, and conversation context are captured intact, so a date-range or per-person request is searchable and exportable on demand.
For your IT team
Server-to-server capture
Comma reads WeCom's server-side archive API directly. Nothing is installed on employee devices, and the WeCom client is not modified.
Per-team scoped keys
Each Comma tenant has its own encrypted credentials and a versioned RSA key pair. Keys are never shared across tenants, and WeCom-side key rotations don't break historical message decryption.
For your employees
WeCom works exactly as it does today
Capture happens through the API, not on the device. Employees keep using WeCom with no change to their experience.
No manual exports
Users do not need to save or export conversations. The record is created automatically.
FAQ about WeChat and WeCom compliance archiving
How does Comma capture WeCom messages?
What exactly gets captured?
Does WeCom activity go into the same archive as our other channels?
Your team is already on WeChat.
Capture WeCom and archive it in the same place as all your other business messages.
Related reading
