Research, positioning, decision records — what lives in Weaxen is among the most sensitive material a company produces. Here is our security posture, stated plainly: what's in place today, and where our assurance programme is headed. No badges we haven't earned.
Held in the UK (AWS London region) by default, with automated backups. Where a region or sector mandates it — UAE health and government data, US federal, sovereign public sector — we adapt to your requirement, up to on-soil hosting.
TLS for every connection, encryption at rest for every byte stored, and HSTS enforced across the product.
Multi-factor authentication for everyone. Enterprise agreements add SAML 2.0 single sign-on with DNS-verified domains — and the option to enforce SSO organisation-wide.
Row-level security in the database backs application-layer authorisation on every action, so one organisation's data is structurally invisible to another.
Organisation-level audit logging of access and configuration changes, and versioned artefacts for every product decision — who, what, when, on what evidence.
PII-scrubbed error monitoring, rate limiting, WAF-fronted edge, and a published vulnerability disclosure policy with a named contact.
Trust pages love to imply certifications. Ours tells you exactly where we are:
Controls are mapped against the SOC 2 Common Criteria and evidence collection is under way. We'll display the report when we've earned it — not a badge before.
An internal penetration test — an adversarial authorisation and injection sweep of the full codebase — has been completed, with all critical and high findings remediated. An external engagement is planned.
We run a published vulnerability disclosure policy. Suspected vulnerabilities go to security@mindlace.co.uk; we acknowledge within three business days and credit reporters with permission.
A current subprocessor inventory and data-processing documentation are available on request — ask at security@mindlace.co.uk.
Evaluating Weaxen for a security-conscious organisation? Email security@mindlace.co.uk and we'll walk your team through the posture directly — architecture, controls, and roadmap.
Your workspace content is never shared with other customers, and we don't use it to train our own models. AI generation runs through contracted model providers under commercial API terms.
Your product research, strategy, and decision records, plus the account details of your team members. Weaxen isn't in the path of your customers' data — it holds your thinking, which is exactly why we treat it as highly confidential.
Yes — data-processing agreements and our subprocessor inventory are part of enterprise onboarding, and available on request at security@mindlace.co.uk.
In the UK by default, and in your region where residency is required — we're fully adaptable to on-soil requirements per region, including the UAE and US. Sovereign and air-gapped deployments are part of how we scope an engagement, not an afterthought. Bring hard hosting constraints early: security@mindlace.co.uk.
For teams who treat "build the right thing" as a precondition, not a slogan. Start for free →