The architecture, security and integrations your enterprise review will ask for.

Weissr Capex is a multi-tenant SaaS platform on AWS, ISO 27001 certified, GDPR-compliant, with global data residency, an on-premises option, single sign-on, full audit logging, and an open integration model. Designed so your IT team, security team, and finance leadership can all say yes.

ISO 27001
certified

GDRP
DPA available for signing

99.99%
Monthly uptime SLA

Global
Any AWS region · on-prem option

FOR YOUR ROLE

The technology decision at a capital-intensive enterprise is never made by one person.

Here is what each of them is really asking, and what Weissr means for them.

CIO / IT Director

You own the vendor security review. You need this to pass — and pass cleanly, on the first submission. Weissr is built to make that happen.

WHAT THIS MEANS FOR YOU

  • ISO 27001 certificate, pen test summary, DPA: dispatched within one business day under NDA
  • SAML 2.0 / OIDC SSO with SCIM provisioning: connects to your IdP without custom development
  • SaaS, single-tenant or on-premises: whichever your deployment policy requires
  • Full audit log exportable to your SIEM. Every user action, approval and data change recorded

01 · ARCHITECTURE

Architecture & Performance

AWS-hosted SaaS, on-prem option, modern browsers, continuous delivery.

02 · AI

AI Capabilities

Data analysis, forecasting, decision augmentation, and an MCP connector for your own agents.

03 · SECURITY

Security & Compliance

ISO 27001, GDPR, encryption end-to-end, SAML SSO, SCIM, RBAC, audit logging.

04 · OPERATIONS

Operations & Support

99.99% uptime, automatic updates, status page, named onboarding team.

01 · ARCHITECTURE

One platform. Your data. Where your policy requires it.

Weissr Capex runs as a multi-tenant SaaS on Amazon Web Services. Tenants are logically isolated, data encrypted at rest and in transit, and your tenant can be provisioned in any AWS region your organisation requires. For organisations whose policy rules out cloud, single-tenant and on-premises are first-class deployment options: same product, same updates.

SaaS, single-tenant or on-premises

Deploy the way your security review allows. No compromise on features.

Global data residency

Choose any AWS region at provisioning. Data does not leave the chosen region, ever.

Scales across sites and entities

Works across 20 production plants in 8 countries, with the same process and governance. Acquired a new entity? Add it in days, not months.

Business users as administrators

Finance teams can configure approval workflows, forms and routing without raising an IT ticket. The process is owned by the business.

Continuous delivery

Automatic, zero-downtime updates. New features and security patches without IT effort or scheduled maintenance windows.

Modern browsers only

Latest Chrome, Edge, Firefox, Safari. No client install. Mobile-responsive.

Weissr technology diagram

Integration technology

Weissr Capex connects to your stack via standards-based identity (SAML 2.0 / OIDC, SCIM 2.0) and a versioned REST API plus webhooks. Three native SAP S/4HANA connectors. Pre-built patterns for Oracle, IFS, and more.

02 · AI CAPABILITIES

AI built into the platform — and open to yours.

Weissr applies AI where it makes capex decisions faster and better: surfacing insights from your data, forecasting outcomes, augmenting day-to-day workflows. AI that works inside your capex process, and open to your own agents through an MCP connector.

Data analysis

Ask Weissr to explain a portfolio, find investments off-strategy, compare scenarios or summarise a budget cycle in plain language. Output is always traceable to the underlying data.

Forecasting

AI-assisted forecasts for project costs, cash phasing and portfolio outcomes, using your own historical data, with confidence intervals and assumptions made visible.

Decision augmentation

AI assists capex teams in their actual workflow, drafting business-case narratives, suggesting risks, flagging projects that drift from strategy, summarising review packs. Humans stay in the loop on every decision.

AI governance: your data stays yours

Customer data is never used to train cross-tenant models. Every AI action runs inside your tenant, with the same role-based access controls and audit logging as a human user. Every retrieval is logged: actor, input, output.

NEW · MCP CONNECTOR

Your own AI agents can plug in too.

Weissr exposes its data through the open Model Context Protocol (MCP). Any AI agent or assistant, including Claude, ChatGPT-style copilots, or your internal tooling, can connect and retrieve capex data on demand. Same RBAC as a human user. Every retrieval audit-logged. No custom integration code required.

03 · SECURITY & COMPLIANCE

Built to clear enterprise security review on the first pass.

ISO 27001 certified, GDPR-compliant, encryption end-to-end, role-based access control, and an audit trail on every meaningful action. Here is the checklist.

Certificate available under NDA via the Trust Documents section below.

DPA available for signing. Sub-processor list published and subscribers notified before changes.

Azure AD / Entra ID, Okta, Google Workspace, ADFS and other SAML/OIDC identity providers supported.

Automated user lifecycle management from your IdP. Just-in-time provisioning supported. Joiners, movers and leavers handled without manual admin.

Inherited from your IdP, or enforced natively when SSO is not in use.

Roles and permissions configurable down to module and entity level. Business users manage their own workflows without IT dependency.

Every action logged with actor, timestamp, before/after values. Nobody changes a number without a record. Retention configurable. Export to your SIEM.

Audit underway. Letter of engagement available on request.

HTTPS enforced across all endpoints. Modern cipher suites. HSTS enabled.

Tenant data, backups and logs encrypted at rest. Customer-managed keys (BYOK) available on Enterprise tier.

Independent third-party tests annually and at every major release. Executive summary available under NDA.

Continuous scanning, dependency monitoring, defined SLA for remediation by severity.

Encrypted backups across AWS availability zones. DR runbooks tested annually.

Provisioned in any AWS region your organisation requires. Data stays in region.

Every AI action runs inside your tenant with the same RBAC and audit logging as a human user. Customer data is never used to train models that benefit other tenants.

Open Model Context Protocol endpoint. Authenticated via your IdP. Per-retrieval audit log with actor, input and result.

Need a specific control framework not listed? Talk to our security team →

04 · OPERATIONS & SUPPORT

Run by people. Monitored by machines. Available when you need it.

Concrete service-level commitments, transparent incident communication, and a named onboarding team that gets your process live on time.

99.99%

Monthly uptime SLA

Multi-AZ deployment on AWS. Service credits if we miss.

RPO 1h · RTO 4h

Disaster recovery

Continuous backups across availability zones. DR runbooks tested annually. You get the results.

1–4 months

Implementation time

Named onboarding team configures workflows, forms and integrations to your process.

24/7

Status & monitoring

Public status page, real-time alerts, named incident contacts on Enterprise. GDPR 72-hour breach notification met.

Software that owns the capital allocation process has to clear enterprise security review. Weissr does that — ISO certified, integrated with the ERP and EAM systems we already run, and the team responds to our security questions within days.

CIO
Global Pulp & Paper Group

Weissr’s implementation process was smooth, and they have met all of our IT security requirements. The fact that it’s a cloud solution with strong data security measures has been a huge benefit for us, especially when handling highly confidential financial data.

IT Manager
European Energy Corporation

What the security and finance leadership ask first.

You choose any AWS region at provisioning, anywhere AWS operates a data centre globally. Your tenant and its backups stay within the chosen region. For organisations whose policy or regulation rules out cloud, single-tenant and on-premises deployments are first-class options with the same product and the same update cadence.

Yes, Weissr is ISO 27001 certified and the certificate is available under NDA via the Trust Documents section. SOC 2 Type II audit is currently in progress; the letter of engagement is available on request.

SAML 2.0 and OpenID Connect, including Azure AD / Entra ID, Okta, Google Workspace, ADFS, Ping and any other compliant SAML/OIDC provider. SCIM 2.0 for automated user lifecycle management. MFA is enforced, either inherited from your IdP or applied natively when SSO is not in use.

Weissr connects to your IdP via SAML or OIDC, provisions users via SCIM, and exposes a versioned REST API and webhooks. Three native SAP S/4HANA connectors are available, along with pre-built patterns for Oracle, IFS and others. Full details on the Integrations page →

Every user action, approval decision, data change and admin event is logged with actor, timestamp, and before/after values where applicable. Retention is configurable. Logs can be exported directly to your SIEM.

Weissr provides AI-based functionality for data analysis, forecasting and decision augmentation, and exposes an MCP connector so your own AI agents and assistants can connect to the platform. All AI actions run inside your tenant, against your data, with the same role-based access controls and audit logging as a human user. Every AI retrieval is logged with actor, input and result. Customer data is never used to train models that benefit other tenants.

The MCP connector exposes Weissr Capex data through the open Model Context Protocol standard. Any AI agent or assistant, including Claude, ChatGPT-style copilots, BI tools, or bespoke internal applications, can connect and retrieve capex data on demand. Authentication runs through your IdP, the same RBAC applies as for human users, and every retrieval is audit-logged. No custom integration code required.

Public status page for real-time service health. Real-time monitoring and alerting on our infrastructure. Named incident contacts on Enterprise tier. Post-incident reviews shared with affected customers. Security incident notifications meet GDPR’s 72-hour requirement.

Yes. On-premises is a first-class deployment option in Weissr Capex. You receive the same product, the same features, and the same update cadence as cloud-hosted customers. Our implementation team handles the setup.

End-to-end implementation typically takes 1–4 months depending on the complexity of your integration environment and the number of entities or workflows to configure. A named onboarding team works directly with your team, configuring Weissr to your process.

TRUST DOCUMENTS

The artefacts your security team needs.

Most of these are available under NDA. Tell us which you need and we will send a complete packet within one business day.

Talk to our security team.

Skip the marketing call. Bring your questionnaire and we will work through it line by line, with the people who actually run our infrastructure and security programme.