Security
Last updated 3 September 2026
This page explains how Wefen protects the scheduling data organisations trust us with. If your governance team needs more than what is here, email
hello@wefenapp.com and we will answer directly.
Certifications
- Cyber Essentials: Certified (profile 3.3, whole organisation), valid to 3 September 2027. Certificate number d7d4d9e5-6427-4071-9593-be26704a775b, independently verifiable on the IASME register.
- NHS Data Security and Protection Toolkit: Standards Met (2025-26), valid to 30 June 2027. Verifiable on the public DSPT register under organisation code X3J4G.
This page carries certificate details as each is issued; each is independently checkable on its public register.
Where your data lives
Wefen runs entirely on Amazon Web Services in the UK (London region). Scheduling data does not leave AWS UK/EU infrastructure in normal operation. Everything is encrypted in transit (TLS) and encrypted at rest.
How access is controlled
- Every user signs in with their own account; passwords require a minimum of 12 characters.
- Administrative access to our infrastructure requires multi-factor authentication throughout.
- Our deployment pipeline holds no standing cloud credentials at all; it authenticates with short-lived, per-run credentials.
- All administrative activity in our infrastructure is logged and retained for 12 months.
Backups and continuity
Production data is backed up continuously: we can restore to any point in the last 35 days, and daily snapshots are retained for 90 days on top. The whole platform is defined as code, so infrastructure can be rebuilt from scratch rather than repaired by hand.
Privacy basics
- Your organisation remains the controller of its staff data; we process it only to provide the service.
- Customer data is retained for the life of the contract plus 90 days, then deleted.
- No analytics or marketing cookies, on the product or this site.
The full detail is in our privacy policy.
Suppliers
| Supplier | Role | Assurance |
| Amazon Web Services | All hosting, UK region | ISO 27001, SOC 2, Cyber Essentials Plus |
| Anthropic | Compiling written scheduling rules | SOC 2 Type II; no training on our data |
| GitHub | Code hosting (no customer data) | SOC 2 Type II |
| Atlassian | Internal tooling | ISO 27001, SOC 2 |
| Microsoft 365 | Business email | ISO 27001, SOC 2 |
Reporting a vulnerability
If you believe you have found a security issue in Wefen or this site, email hello@wefenapp.com. We read every report, respond quickly, and will not take action against good-faith research. Machine-readable details are published at /.well-known/security.txt.