Security and privacy
Built for PHI from day one
Weave reads your most sensitive data, so security isn't a feature we added. It decides how every part of the platform is built.
HIPAA
Business AssociateBAA signed with every customer before any patient data connects.
SOC 2 Type II
Audited annuallySecurity, availability, and confidentiality, audited by an independent firm.
HITRUST CSF
r2 certifiedCertified against the framework most health systems already assess vendors with.
Audit reports are available under NDA. Request them from our team.
How we protect your data
Six things that are true on every plan
01
Encrypted everywhere
AES-256 at rest and TLS 1.3 in transit. Keys are held in a managed HSM and can be customer-managed on Enterprise.
02
Isolated by design
Each customer runs in a dedicated tenant, or entirely inside their own cloud. Data is never pooled across customers.
03
Least-privilege access
SSO and SCIM provisioning, role-based permissions down to the source, and no standing access for Weave staff.
04
Every access logged
Who looked at what, when, and why, kept for seven years and exportable to your SIEM at any time.
05
US data residency
Patient data is stored and processed in US regions only, with backups in a second region for recovery.
06
Tested continuously
Annual third-party penetration tests, continuous vulnerability scanning, and a public disclosure programme.
Audit log
Every access, on the record
People and products alike. When Consult answers a question, the log shows whose question it was and which records it read.
Access logRecording
Today · Alder Bay Health
- 09:42:17M. OkaforCare coordinatorViewed · Patient 4471-A · labs
- 09:41:03ConsultQuery on behalf of T. LindqvistQueried · Post-op unit · lactate trend
- 09:38:55R. SolísClinical data leadExported · Readmissions report · Q3
- 09:36:12AtlasScheduled syncRead · Pharmacy feed · 2,184 records
- 09:31:48J. ParkIT administratorChanged · Role · Nurse manager permissions
Your data, your rules
What we'll never do with it
- Your data is never used to train models, ours or anyone else's.
- Your data is never sold, shared, or used for advertising.
- You can export everything, in open formats, at any time.
- On termination, your data is deleted within 30 days, with a certificate of destruction.
Security review
Send us your questionnaire, whether it's a SIG, a CAIQ, or your own. We return most within five business days.
Report a vulnerability
Found something? Tell our security team. We acknowledge every report within one business day and never pursue good-faith research.