Security and Privacy
Data security and privacy at Weave Bio are central to how we operate. Weave is an AI-native software company that provides a cloud-based platform to support the regulatory lifecycle. As a SaaS solution provider, Weave maintains policies with a strong commitment to data security and privacy.
Weave is SOC 2 Type II certified, with controls independently assessed for both design and operating effectiveness.
Security pillars
Zero data retention
Customer data is never retained by our model providers.
TLS & AES-256 encryption
Encrypted in transit and at rest.
MFA & role-based access
Enforced across all systems.
Continuous monitoring
Audited continuously.
How your data is handled
When organizations license our platform, we collect authorized user names and corporate email addresses for account creation. We also use Amplitude to collect product usage statistics, feature use and browser information, to maintain uptime, address bugs, and inform improvements.
All files uploaded to the platform are considered customer data. Authorized users have access only to their own organization’s data, including approved consultants and partners provisioned at the request of a contracted customer. Only provisioned Weave team members have access, granted on a need-to-know basis and removed as soon as it’s no longer required. If Weave ever needs to use customer data for another purpose, we’ll request explicit permission.
Infrastructure
OpenAI
Our LLM provider, operating under a formal Zero Data Retention policy.
Amazon Bedrock
Used for content extraction from customer files. Does not retain customer data.
Model updates ship only after they’ve been vetted for improvements and passed our regression test suite.
Resilience and disaster recovery
The Weave Platform’s infrastructure is built for regional failover. Daily snapshots are retained for a minimum of 30 days and copied to a backup AWS region, with a continuously updated standby database ready to take over if the primary region fails.
You’re in control
Once your organization’s account is created, you have complete control over access and permission levels, and can delete data or remove user access at any time. A contracted security team conducts regular audits of our corporate, application, and infrastructure security, with continuous monitoring for anomalous behavior.
Found a security issue? Report it to security@weave.bio