How Weavwork protects your data
Last updated: 2 September 2026
Weavwork holds the records a manufacturing business runs on — orders, customers, suppliers, costings. We treat that responsibility plainly: this page describes how the platform is built and operated, and we keep it current as our practices evolve.
Where your data lives
Weavwork runs on Amazon Web Services infrastructure. Each customer’s workspace is logically isolated in our multi-tenant architecture: your records are always scoped to your tenant, and portal users (your customers and suppliers) see only the records you have shared with them.
Encryption
All traffic between your browser and Weavwork is encrypted in transit with TLS, and data is stored on AWS services with encryption at rest enabled.
Access control
Within your workspace, role-based permissions control who can see and change what — including portal-level roles for external customers and suppliers. Within Weavwork the company, access to production systems is limited to the engineers who operate them, protected by multi-factor authentication, and logged.
Backups and continuity
Customer data is backed up daily, with backups retained for 30 days, and restore procedures are tested regularly.
Development practices
Changes ship through code review and automated checks before reaching production. Dependencies are monitored for known vulnerabilities. Sample or invented data — never customer data — is used in development and in marketing material.
Your data is yours
Every record can be exported in open formats at any time, and when you leave Weavwork your data is returned or deleted per the customer agreement.
Reporting a vulnerability
If you believe you have found a security issue in Weavwork, email security@weavwork.com. We acknowledge reports promptly, keep you informed while we investigate, and do not pursue good-faith research conducted responsibly.