Weissr

Capex Platform · Security & Governance

Built for enterprise security reviewand reliable operation afterwards.

Architecture, security and governance for the IT, finance and risk teams responsible for reviewing the platform and operating it over time.

Weissr security and governance panel showing ISO 27001 certification, EU data residency, 99.5% SLA and role-based access
99.5% SLA

ISO 27001

Certified information security

99.5%

Monthly uptime SLA

RPO 1h

RTO 4h disaster recovery

Global

Regional or on-prem deployment

Architecture

One platformdeployed where policy requires it.

Apply the same identity, deployment and operating standards across sites and legal entities.

01 / 06

Deployment that fits policy

Single-tenant SaaS as standard, with on-premises deployment available, the same product and update cadence.

02 / 06

Global data residency

Provision in the required AWS region and keep tenant data and backups inside that region.

03 / 06

Business-owned configuration

Finance configures workflows, forms and routing without routine IT tickets.

04 / 06

Enterprise identity

SAML 2.0, OIDC, SCIM 2.0 and MFA through leading identity providers.

05 / 06

Complete audit record

Capture actor, timestamp and before-and-after values; export records to your SIEM.

06 / 06

Continuously operated

Zero-downtime delivery, vulnerability monitoring and a public service status page.

Security & compliance

The controls requiredfor enterprise review.

01ISO 27001Certified

The certificate is available under NDA together with the supporting security documentation.

02GDPRDPA available for signing

Data processing terms, a published sub-processor list and change notification support enterprise privacy reviews.

03EncryptionTLS 1.2+ in transit · AES-256 at rest

Tenant data, backups and logs are encrypted. Customer-managed keys are available on the Enterprise tier.

04Role-based accessGranular to module and entity level

Permissions apply consistently to people, integrations and AI capabilities across the platform.

05Penetration testingAnnually and on major releases

Independent testing complements continuous scanning, dependency monitoring and severity-based remediation targets.

06Backup and recoveryRPO 1 hour · RTO 4 hours

Encrypted backups span availability zones and disaster-recovery runbooks are tested annually.

07AI governanceTenant-scoped and audit-logged

AI uses the same access controls as a human user. Customer data is not used to train cross-tenant models.

For every stakeholder

IT can approve it.Finance can own it.

  • Security documents supplied under NDA for formal review
  • SSO and automated provisioning without custom development
  • Every approval and data change remains traceable
  • New entities inherit the same governance in days
  • Named onboarding team and 1–4 month implementation
  • Business users manage the process without weakening controls

Bring your enterprisesecurity questionnaire.

Talk directly with the people responsible for the architecture and security programme.

Book a demo