Trust & Security
WeGen processes website data for conformance analysis. We take the security and privacy of that data seriously. This page documents our practices, commitments, and roadmap.
Data Encryption
All data is encrypted in transit and at rest.
- TLS 1.2+ for all connections (HTTPS enforced)
- AES-256 encryption for stored data
- Database-level encryption via Supabase (AWS infrastructure)
- No sensitive data stored in client-side storage or cookies
Access Control
Strict access controls limit who can see what data.
- Role-based access control (RBAC) for all user accounts
- Row-level security (RLS) policies on all database tables
- PIN-protected client report access
- View tracking on all shared reports
- No shared credentials or generic admin accounts
What We Scan
WeGen only analyzes publicly accessible web content.
- We scan publicly visible pages, not internal systems or servers
- No credentials, passwords, or authentication tokens are collected
- No personal data from website visitors is captured
- Scan results are shared only with the authorized requesting client
- We do not sell, share, or monetize scan data
Data Retention
We retain data only as long as necessary for service delivery.
- Active scan results retained for the duration of the service agreement
- Historical scan data retained for trend analysis and drift detection
- Client data deleted upon request within 30 days
- No data sold or shared with third parties for marketing
- Backup data encrypted and retained for 90 days maximum
Infrastructure Security
Built on managed cloud infrastructure with enforced security controls.
- Hosted on Netlify (CDN) and Supabase (PostgreSQL on AWS)
- Security headers enforced: CSP, HSTS, X-Frame-Options
- DKIM, SPF, and DMARC email authentication configured
- No open ports, no SSH access, no exposed admin panels
Incident Response
Clear process for handling security events.
- Security incidents acknowledged within 24 hours
- Affected clients notified within 72 hours of confirmed breach
- Post-incident review and remediation documented
- Contact: zeerohr@wegendigital.com
Roadmap
DKIM / SPF / DMARC Email Authentication
All outbound email authenticated with strict alignment policies.
Security Headers
CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy enforced on all pages.
Privacy Policy
Published at /privacy. Covers data collection, retention, and user rights.
security.txt
Responsible disclosure contact published at /.well-known/security.txt.
WOSB Certification
Woman-Owned Small Business certification through SBA third-party review.
SAM.gov Registration
Federal vendor registration. In progress.
SOC 2 Type II
Formal SOC 2 Type II audit planned. Current practices align with Trust Services Criteria for Security, Availability, and Confidentiality.
Data Processing Addendum (DPA)
Standard DPA template for enterprise clients requiring contractual data protection commitments.
Subprocessors
| Provider | Purpose | Data Processed | Location |
|---|---|---|---|
| Supabase | Database, authentication, storage | User accounts, scan results, reports | US (AWS) |
| Netlify | Website hosting, CDN, serverless functions | Static assets, server-side processing | US (Global CDN) |
| Google Workspace | Business email | Email communications | US |
Responsible Disclosure
Found a security vulnerability? We appreciate responsible disclosure.
Email zeerohr@wegendigital.com with details. We will acknowledge receipt within 24 hours and provide an initial assessment within 72 hours.
We do not operate a bug bounty program at this time. We will not pursue legal action against researchers who report vulnerabilities in good faith.
WeGen is a conformance review tool. Results are informational only and do not constitute legal or regulatory advice. Organizations should consult qualified legal counsel for their specific situations.