Third Party Index

Snapshot 55207

Document
Security page
URL
https://weld.app/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
185057 bytes
SHA-256 (raw)
7b84f2c63d9cc443c51335682630993ed5a01e548891f135455fdb3d9c46dcff
SHA-256 (normalized text)
8344571e4279a17008d47e8cbca94c642fd0de9a48b29e150650da50664706a7

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Security
Built and designed for data security and privacy.
How Weld protects the data it moves, and the evidence your security and procurement teams will ask for.
Request SOC reportsData Processing Agreement
Last updated Oct 2, 2026 · 8 min read
Audit
SOC 2 Type II
Independent audit with continuous controls. SOC 2 Type II report under NDA, SOC 3 report on request.
Request report
Testing
Penetration tested
The Weld platform is penetration tested, on top of the SOC 2 Type II audit.
Infrastructure
AWS and Google Cloud
Weld runs in AWS and Google Cloud data centres certified to SOC 2 and ISO 27001.
Privacy
GDPR compliant
Privacy by design, with a public DPA and subprocessor list. Hosted in the EU.
DPASubprocessors
Audited by
01
Executive summary
Weld moves data securely between your systems and your warehouse with a defense-in-depth approach: strong encryption (in transit and at rest), least-privilege access, secure SDLC, rigorous monitoring, and audited controls. We minimize data handling, prefer ephemeral processing, and keep transparent evidence for your procurement teams.
Encryption in transit and at rest
TLS 1.2+ in transit; strong at rest.
Least-privilege access
RBAC, SSO/MFA, audited elevation.
Secure SDLC
Reviews, SCA, scanning, staged deploys.
Transparency
Public policies, evidence on request.
02
Data flow & architecture
Weld extracts from approved sources, transports via secure channels, and loads into your destination (e.g., Snowflake, BigQuery, Databricks, Postgres). Processing is ephemeral, and customer data is not retained beyond what’s required to perform the sync, unless it is stored in a Weld managed data warehouse.
Sources
Apps / DBs / Files
Weld (ETL)
Ephemeral processing
Destination
Warehouse / Lakehouse
Hosted in the EU on AWS and Google Cloud.
Private subnets for core services; public ingress via hardened gateways.
Secrets in managed KMS; zero secrets in code or repos.
03
Encryption
TLS 1.2+ for all connections; HSTS enforced on app endpoints.
Strong at-rest encryption for managed stores; customer KMS respected where available.
Key rotation per provider recommendations; strict IAM on key usage.
We avoid storing customer data whenever possible. ETL buffers are ephemeral and scoped to the job lifecycle.
04
Access & identity
SSO/MFA enforced for console access; RBAC with least privilege.
Break-glass access requires approvals and is fully audited.
SCIM/automatic deprovisioning supported on eligible plans.
2FA
TLS
SOC 2 II
05
Secure SDLC
Code review & CI checks (linting, unit/integration tests, SCA).
Secrets management, dependency pinning, image scanning.
Change management with approvals; staged rollouts and canaries.
06
Monitoring & incident response
Centralized logging, metrics, and traces for all services.
24/7 on-call rotation; automated alerting for anomalous events.
Documented IR plan with communication runbooks and post-mortems.
See our status page for uptime and incident history.
07
Backups, DR & BCP
Backups with tested restores; RTO/RPO objectives documented.
Multi-AZ by default; region recovery procedures maintained.
BCP reviews annually and after material changes.
08
Compliance & evidence
SOC 2 Type II: independent audit with continuous controls, report available under NDA, and a SOC 3 report on request. Penetration testing: the Weld platform is penetration tested. Infrastructure: Weld runs on AWS and Google Cloud, whose data centres are certified to SOC 2 and ISO 27001.
Public policies: Data Processing Agreement · Subprocessors
09
Resources & contacts
Data Processing AgreementSubprocessorsRequest SOC reportsVulnerability disclosure