Wefen

Security

Last updated 18 August 2026

This page explains how Wefen protects the scheduling data organisations trust us with. If your governance team needs more than what is here, email hello@wefenapp.com and we will answer directly.

Certifications

This page carries certificate details as each is issued; each is independently checkable on its public register.

Where your data lives

Wefen runs entirely on Amazon Web Services in the UK (London region). Scheduling data does not leave AWS UK/EU infrastructure in normal operation. Everything is encrypted in transit (TLS) and encrypted at rest.

How access is controlled

Backups and continuity

Production data is backed up continuously: we can restore to any point in the last 35 days, and daily snapshots are retained for 90 days on top. The whole platform is defined as code, so infrastructure can be rebuilt from scratch rather than repaired by hand.

Privacy basics

The full detail is in our privacy policy.

Suppliers

SupplierRoleAssurance
Amazon Web ServicesAll hosting, UK regionISO 27001, SOC 2, Cyber Essentials Plus
AnthropicCompiling written scheduling rulesSOC 2 Type II; no training on our data
GitHubCode hosting (no customer data)SOC 2 Type II
AtlassianInternal toolingISO 27001, SOC 2

Reporting a vulnerability

If you believe you have found a security issue in Wefen or this site, email hello@wefenapp.com. We read every report, respond quickly, and will not take action against good-faith research. Machine-readable details are published at /.well-known/security.txt.