Security and Privacy

Data security and privacy at Weave Bio are central to how we operate. Weave is an AI-native software company that provides a cloud-based platform to support the regulatory lifecycle. As a SaaS solution provider, Weave maintains policies with a strong commitment to data security and privacy.

Icon - A-lign SOC 2

Weave is SOC 2 Type II certified, with controls independently assessed for both design and operating effectiveness.

Security pillars

Document Delete

Zero data retention

Customer data is never retained by our model providers.

TLS & AES-256 encryption

Encrypted in transit and at rest.

MFA & role-based access

Enforced across all systems.

Continuous monitoring

Audited continuously.

How your data is handled

When organizations license our platform, we collect authorized user names and corporate email addresses for account creation. We also use Amplitude to collect product usage statistics, feature use and browser information, to maintain uptime, address bugs, and inform improvements.

All files uploaded to the platform are considered customer data. Authorized users have access only to their own organization’s data, including approved consultants and partners provisioned at the request of a contracted customer. Only provisioned Weave team members have access, granted on a need-to-know basis and removed as soon as it’s no longer required. If Weave ever needs to use customer data for another purpose, we’ll request explicit permission.

Infrastructure

OpenAI Logo

OpenAI

Our LLM provider, operating under a formal Zero Data Retention policy.

Amazon Bedrock Logo

Amazon Bedrock

Used for content extraction from customer files. Does not retain customer data.

Model updates ship only after they’ve been vetted for improvements and passed our regression test suite.

Resilience and disaster recovery

The Weave Platform’s infrastructure is built for regional failover. Daily snapshots are retained for a minimum of 30 days and copied to a backup AWS region, with a continuously updated standby database ready to take over if the primary region fails.

You’re in control

Once your organization’s account is created, you have complete control over access and permission levels, and can delete data or remove user access at any time. A contracted security team conducts regular audits of our corporate, application, and infrastructure security, with continuous monitoring for anomalous behavior.

Found a security issue? Report it to security@weave.bio

Request our SOC 2 report