Trust

Security.

What we do to keep customer data safe, and how to tell us if we have missed something.

Last updated 1 July 2026

Our starting position

Weft holds records that customers may one day need to rely on in front of a regulator or a court. That sets the bar: data has to be intact, attributable and available, not merely private.

Data in transit and at rest

  • All traffic to our services is encrypted in transit using current TLS.
  • Stored data is encrypted at rest, with keys managed by our cloud provider’s key management service.
  • Readers queue measurements locally in encrypted storage when offline and reconcile on reconnect.

Access

  • Customer data is segregated per tenant.
  • Access follows least privilege, is granted by role, and is reviewed on a schedule.
  • Staff access to production requires multi-factor authentication and is logged.
  • Single sign-on and role-based permissions are available to customers.

Integrity of the record

Readings are written as append-only events. Corrections are recorded as new entries rather than edits, so a record can be explained rather than merely trusted. Exports include the full history.

Resilience

  • Automated backups with tested restores.
  • Infrastructure defined in code and deployed through reviewed pipelines.
  • Monitoring and alerting on availability, error rates and unusual access.

Development practice

  • Peer review before merge, with automated dependency and secret scanning.
  • Separate development, staging and production environments.
  • Independent penetration testing on a recurring basis.

Vendors

We keep the number of processors small and assess each before use. A current list, along with our data processing terms and the status of any formal audits or certifications, is available to customers and prospects on request.

Incidents

We investigate suspected incidents immediately, notify affected customers without undue delay, and follow up with a written account of what happened and what changed as a result.

Reporting a vulnerability

Send findings to security@weft.co. Please give us reasonable time to fix an issue before disclosing it. We do not pursue researchers who act in good faith, stay within scope and avoid accessing other people’s data.

Questions from procurement

Security questionnaires, architecture detail and subprocessor lists go to security@weft.co. We would rather answer properly than quickly.