Weaxen
Product
PricingSecurityCommunity
Trust & Security

Weaxen holds your product strategy. We built it like we understand that.

Research, positioning, decision records — what lives in Weaxen is among the most sensitive material a company produces. Here is our security posture, stated plainly: what's in place today, and where our assurance programme is headed. No badges we haven't earned.

Request Security DocumentationGovernment & Public Sector

In place today

Data residency you control

Held in the UK (AWS London region) by default, with automated backups. Where a region or sector mandates it — UAE health and government data, US federal, sovereign public sector — we adapt to your requirement, up to on-soil hosting.

Encryption everywhere

TLS for every connection, encryption at rest for every byte stored, and HSTS enforced across the product.

Identity & access

Multi-factor authentication for everyone. Enterprise agreements add SAML 2.0 single sign-on with DNS-verified domains — and the option to enforce SSO organisation-wide.

Tenant isolation

Row-level security in the database backs application-layer authorisation on every action, so one organisation's data is structurally invisible to another.

Audit trail

Organisation-level audit logging of access and configuration changes, and versioned artefacts for every product decision — who, what, when, on what evidence.

Monitoring & response

PII-scrubbed error monitoring, rate limiting, WAF-fronted edge, and a published vulnerability disclosure policy with a named contact.

Our assurance programme

Trust pages love to imply certifications. Ours tells you exactly where we are:

SOC 2 programme in progress

Controls are mapped against the SOC 2 Common Criteria and evidence collection is under way. We'll display the report when we've earned it — not a badge before.

Adversarial security testing

An internal penetration test — an adversarial authorisation and injection sweep of the full codebase — has been completed, with all critical and high findings remediated. An external engagement is planned.

Responsible disclosure

We run a published vulnerability disclosure policy. Suspected vulnerabilities go to security@mindlace.co.uk; we acknowledge within three business days and credit reporters with permission.

Subprocessors & DPAs

A current subprocessor inventory and data-processing documentation are available on request — ask at security@mindlace.co.uk.

Evaluating Weaxen for a security-conscious organisation? Email security@mindlace.co.uk and we'll walk your team through the posture directly — architecture, controls, and roadmap.

Security questions, answered straight

Is our data used to train AI models?

Your workspace content is never shared with other customers, and we don't use it to train our own models. AI generation runs through contracted model providers under commercial API terms.

What kind of data does Weaxen hold?

Your product research, strategy, and decision records, plus the account details of your team members. Weaxen isn't in the path of your customers' data — it holds your thinking, which is exactly why we treat it as highly confidential.

Can we get a DPA?

Yes — data-processing agreements and our subprocessor inventory are part of enterprise onboarding, and available on request at security@mindlace.co.uk.

Where can our data be hosted?

In the UK by default, and in your region where residency is required — we're fully adaptable to on-soil requirements per region, including the UAE and US. Sovereign and air-gapped deployments are part of how we scope an engagement, not an afterthought. Bring hard hosting constraints early: security@mindlace.co.uk.

Bring a real initiative. Leave with a real Project Kit.

For teams who treat "build the right thing" as a precondition, not a slogan. Start for free →

Get StartedSee Community Projects