Skip to content

Security and privacy

Built for PHI from day one

Weave reads your most sensitive data, so security isn't a feature we added. It decides how every part of the platform is built.

HIPAA

Business Associate

BAA signed with every customer before any patient data connects.

SOC 2 Type II

Audited annually

Security, availability, and confidentiality, audited by an independent firm.

HITRUST CSF

r2 certified

Certified against the framework most health systems already assess vendors with.

Audit reports are available under NDA. Request them from our team.

How we protect your data

Six things that are true on every plan

01

Encrypted everywhere

AES-256 at rest and TLS 1.3 in transit. Keys are held in a managed HSM and can be customer-managed on Enterprise.

02

Isolated by design

Each customer runs in a dedicated tenant, or entirely inside their own cloud. Data is never pooled across customers.

03

Least-privilege access

SSO and SCIM provisioning, role-based permissions down to the source, and no standing access for Weave staff.

04

Every access logged

Who looked at what, when, and why, kept for seven years and exportable to your SIEM at any time.

05

US data residency

Patient data is stored and processed in US regions only, with backups in a second region for recovery.

06

Tested continuously

Annual third-party penetration tests, continuous vulnerability scanning, and a public disclosure programme.

Audit log

Every access, on the record

People and products alike. When Consult answers a question, the log shows whose question it was and which records it read.

Access logRecording

Today · Alder Bay Health

  1. 09:42:17M. OkaforCare coordinatorViewed · Patient 4471-A · labs
  2. 09:41:03ConsultQuery on behalf of T. LindqvistQueried · Post-op unit · lactate trend
  3. 09:38:55R. SolísClinical data leadExported · Readmissions report · Q3
  4. 09:36:12AtlasScheduled syncRead · Pharmacy feed · 2,184 records
  5. 09:31:48J. ParkIT administratorChanged · Role · Nurse manager permissions

Your data, your rules

What we'll never do with it

  • Your data is never used to train models, ours or anyone else's.
  • Your data is never sold, shared, or used for advertising.
  • You can export everything, in open formats, at any time.
  • On termination, your data is deleted within 30 days, with a certificate of destruction.

Security review

Send us your questionnaire, whether it's a SIG, a CAIQ, or your own. We return most within five business days.

Report a vulnerability

Found something? Tell our security team. We acknowledge every report within one business day and never pursue good-faith research.