Data Security

Your Data Security Is Our Priority

Our operating procedures and coding standards use the most up to date security best practices and protocols to ensure your data remains your data.

Your Security Matters

Enterprise-Grade Security, Built In

From SOC 2 Type II certification to FDA 21 CFR Part 11 compliance, Weever is built on security practices that meet the standards your regulators, auditors, and IT team expect. Explore how we protect your data at every layer, from login to storage.

SOC 2 Type II Certified

Independently audited information security policies and practices.

FDA 21 CFR Part 11 Compliant

Certified for electronic records and signatures, plus EU Annex 11.

GDPR & Data Privacy

EU and UK GDPR compliant, with no sale or brokering of your data.

Single Sign-On (SSO)

One login, fully integrated with your existing identity provider.

Data Encryption

ata is encrypted at login, in transit, and at rest.

Monitoring & Response

Ongoing vulnerability testing, SIEM reporting, and 24 hour breach notification.

SOC 2 Type II Certified

Weever is a SOC 2 Type II compliant service organization. This requires Weever to create and follow strict information security policies covering everything from access management to incident response, and to have those policies independently verified on a recurring basis.

Weever's cloud-based applications are also hosted on a secure, SOC 2 Type II compliant cloud provider, adding a second layer of independently audited infrastructure security beneath our own.

Contact us for a copy of our most recent SOC 2 Type II audit report.

FDA 21 CFR Part 11 Compliant

Weever Process is certified as compliant to FDA regulation 21 CFR Part 11 (Electronic Records and Signatures) and EU Annex 11 (Computerized Systems). For manufacturers operating under FDA or EU regulatory oversight, this means your electronic records, e-signatures, and audit trails in Weever meet the same standards regulators expect from paper based systems, without slowing your team down.

Weever performs full scope internal audits against 21 CFR Part 11 on a recurring basis, alongside ongoing training and policy reviews.

GDPR & Data Privacy

The General Data Protection Regulation (GDPR) sets guidelines for how personal information belonging to individuals in the EU is collected and processed. Weever observes EU and UK GDPR compliance guidelines, including recurring data privacy reviews (DPIA, PIA) and a maintained Record of Processing Activities (ROPA) under GDPR Article 30.

Weever categorically refrains from selling or brokering any personal data or customer data, under any circumstances. A limited subset of non-sensitive data may be shared with third-party providers strictly for service analytics, in order to improve our products.

See our Data Privacy Statement for full details on how we safeguard customer and user privacy.

Single Sign-On (SSO)

Single Sign-On (SSO) combines your team's various application logins into one secure sign-in, so operators and administrators don't need to manage separate Weever credentials. Weever currently supports Okta and Active Directory SSO, allowing your IT team to manage Weever access through the identity provider you already use.

Data Encryption

All Weever applications encrypt data at login, in transit, and at rest, meeting industry best practice encryption standards. Access to data is provisioned on a secure, per-user basis tied to a maintained access matrix, so users only see what their role requires.

All server and application code access is VPN restricted and MFA accessed, and encryption practices are manually verified as part of our recurring security activities, including manual penetration testing.

Continuous Monitoring & Incident Response

Security isn't a one-time setup at Weever, it's a recurring practice. We maintain web application firewalls (WAF) and intrusion detection systems, run independent penetration and vulnerability testing, and produce Security Information and Event Monitoring (SIEM) reports across all key systems. Our FDA compliant products include an administrator-facing SIEM report as well.

In the event of a data breach or critical security vulnerability, clients are notified within 24 hours (or per contract terms), and our SLA for critical patches is 14 days, with high severity patches addressed within 30 days.