Your data stays your data.
Weaver is designed with isolation as a foundation, not an afterthought. Here is how we protect your code, credentials, and context across every tier.
Data isolation by design
Every record is bound to your organization at the data layer. Org-scoping is enforced on every query, so a missing filter cannot leak data across accounts. Isolation is structural, not a policy you have to trust.
Bring your own keys (BYOK)
You run agents on your own model-provider keys, so the credentials that reach providers stay under your control. They are injected into isolated execution at run time and are never used to serve other tenants.
Isolated execution sandboxes
Agent work runs inside per-run, provisioned sandboxes rather than a shared host. Each run gets a clean, controlled environment, so one tenant's execution never shares state with another.
Encryption in transit
Traffic between your browser, our API, and the services behind it is encrypted in transit over TLS. Deep links into the product and checkout are served over HTTPS end to end.
Scoped, auditable access
Access is scoped to each approved plan: agents act through reviewable, bounded permissions rather than an open-ended session. What runs, and on whose behalf, is auditable from start to finish.
Only the context you connect
Weaver operates on the repositories, integrations, and signals you explicitly connect. You choose what the platform can see, and connections can be revoked from your workspace.
Sub-processors
We rely on a small set of vetted infrastructure providers to operate Weaver. The current list is published and kept up to date, including each provider's purpose and processing region.
View sub-processorsResponsible disclosure
Think you have found a vulnerability? We want to hear from you. Report it privately and we will work with you to confirm, remediate, and credit the finding.
Report a security issue