Snapshot 55207
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Security Built and designed for data security and privacy. How Weld protects the data it moves, and the evidence your security and procurement teams will ask for. Request SOC reportsData Processing Agreement Last updated Oct 2, 2026 · 8 min read Audit SOC 2 Type II Independent audit with continuous controls. SOC 2 Type II report under NDA, SOC 3 report on request. Request report Testing Penetration tested The Weld platform is penetration tested, on top of the SOC 2 Type II audit. Infrastructure AWS and Google Cloud Weld runs in AWS and Google Cloud data centres certified to SOC 2 and ISO 27001. Privacy GDPR compliant Privacy by design, with a public DPA and subprocessor list. Hosted in the EU. DPASubprocessors Audited by 01 Executive summary Weld moves data securely between your systems and your warehouse with a defense-in-depth approach: strong encryption (in transit and at rest), least-privilege access, secure SDLC, rigorous monitoring, and audited controls. We minimize data handling, prefer ephemeral processing, and keep transparent evidence for your procurement teams. Encryption in transit and at rest TLS 1.2+ in transit; strong at rest. Least-privilege access RBAC, SSO/MFA, audited elevation. Secure SDLC Reviews, SCA, scanning, staged deploys. Transparency Public policies, evidence on request. 02 Data flow & architecture Weld extracts from approved sources, transports via secure channels, and loads into your destination (e.g., Snowflake, BigQuery, Databricks, Postgres). Processing is ephemeral, and customer data is not retained beyond what’s required to perform the sync, unless it is stored in a Weld managed data warehouse. Sources Apps / DBs / Files Weld (ETL) Ephemeral processing Destination Warehouse / Lakehouse Hosted in the EU on AWS and Google Cloud. Private subnets for core services; public ingress via hardened gateways. Secrets in managed KMS; zero secrets in code or repos. 03 Encryption TLS 1.2+ for all connections; HSTS enforced on app endpoints. Strong at-rest encryption for managed stores; customer KMS respected where available. Key rotation per provider recommendations; strict IAM on key usage. We avoid storing customer data whenever possible. ETL buffers are ephemeral and scoped to the job lifecycle. 04 Access & identity SSO/MFA enforced for console access; RBAC with least privilege. Break-glass access requires approvals and is fully audited. SCIM/automatic deprovisioning supported on eligible plans. 2FA TLS SOC 2 II 05 Secure SDLC Code review & CI checks (linting, unit/integration tests, SCA). Secrets management, dependency pinning, image scanning. Change management with approvals; staged rollouts and canaries. 06 Monitoring & incident response Centralized logging, metrics, and traces for all services. 24/7 on-call rotation; automated alerting for anomalous events. Documented IR plan with communication runbooks and post-mortems. See our status page for uptime and incident history. 07 Backups, DR & BCP Backups with tested restores; RTO/RPO objectives documented. Multi-AZ by default; region recovery procedures maintained. BCP reviews annually and after material changes. 08 Compliance & evidence SOC 2 Type II: independent audit with continuous controls, report available under NDA, and a SOC 3 report on request. Penetration testing: the Weld platform is penetration tested. Infrastructure: Weld runs on AWS and Google Cloud, whose data centres are certified to SOC 2 and ISO 27001. Public policies: Data Processing Agreement · Subprocessors 09 Resources & contacts Data Processing AgreementSubprocessorsRequest SOC reportsVulnerability disclosure