Trust & Security

WeGen processes website data for conformance analysis. We take the security and privacy of that data seriously. This page documents our practices, commitments, and roadmap.

All systems operational. WeGen is fully available.
🔒

Data Encryption

All data is encrypted in transit and at rest.

  • TLS 1.2+ for all connections (HTTPS enforced)
  • AES-256 encryption for stored data
  • Database-level encryption via Supabase (AWS infrastructure)
  • No sensitive data stored in client-side storage or cookies
🛡

Access Control

Strict access controls limit who can see what data.

  • Role-based access control (RBAC) for all user accounts
  • Row-level security (RLS) policies on all database tables
  • PIN-protected client report access
  • View tracking on all shared reports
  • No shared credentials or generic admin accounts
🔍

What We Scan

WeGen only analyzes publicly accessible web content.

  • We scan publicly visible pages, not internal systems or servers
  • No credentials, passwords, or authentication tokens are collected
  • No personal data from website visitors is captured
  • Scan results are shared only with the authorized requesting client
  • We do not sell, share, or monetize scan data
🕐

Data Retention

We retain data only as long as necessary for service delivery.

  • Active scan results retained for the duration of the service agreement
  • Historical scan data retained for trend analysis and drift detection
  • Client data deleted upon request within 30 days
  • No data sold or shared with third parties for marketing
  • Backup data encrypted and retained for 90 days maximum
🔧

Infrastructure Security

Built on managed cloud infrastructure with enforced security controls.

  • Hosted on Netlify (CDN) and Supabase (PostgreSQL on AWS)
  • Security headers enforced: CSP, HSTS, X-Frame-Options
  • DKIM, SPF, and DMARC email authentication configured
  • No open ports, no SSH access, no exposed admin panels
🚨

Incident Response

Clear process for handling security events.

  • Security incidents acknowledged within 24 hours
  • Affected clients notified within 72 hours of confirmed breach
  • Post-incident review and remediation documented
  • Contact: zeerohr@wegendigital.com

Roadmap

Live

DKIM / SPF / DMARC Email Authentication

All outbound email authenticated with strict alignment policies.

Live

Security Headers

CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy enforced on all pages.

Live

Privacy Policy

Published at /privacy. Covers data collection, retention, and user rights.

Live

security.txt

Responsible disclosure contact published at /.well-known/security.txt.

In Progress

WOSB Certification

Woman-Owned Small Business certification through SBA third-party review.

In Progress

SAM.gov Registration

Federal vendor registration. In progress.

Planned

SOC 2 Type II

Formal SOC 2 Type II audit planned. Current practices align with Trust Services Criteria for Security, Availability, and Confidentiality.

Planned

Data Processing Addendum (DPA)

Standard DPA template for enterprise clients requiring contractual data protection commitments.

Subprocessors

Provider Purpose Data Processed Location
Supabase Database, authentication, storage User accounts, scan results, reports US (AWS)
Netlify Website hosting, CDN, serverless functions Static assets, server-side processing US (Global CDN)
Google Workspace Business email Email communications US

Responsible Disclosure

Found a security vulnerability? We appreciate responsible disclosure.

Email zeerohr@wegendigital.com with details. We will acknowledge receipt within 24 hours and provide an initial assessment within 72 hours.

We do not operate a bug bounty program at this time. We will not pursue legal action against researchers who report vulnerabilities in good faith.

WeGen is a conformance review tool. Results are informational only and do not constitute legal or regulatory advice. Organizations should consult qualified legal counsel for their specific situations.