Security

Last updated: July 2026

Wehealt handles sensitive claims and coverage data on behalf of insurers, advisors, and the people they serve. Security is built into the platform at every layer, from infrastructure to day-to-day operations.

Encryption

Data is encrypted in transit using TLS and at rest using industry-standard encryption. Encryption keys are managed separately from the data they protect.

Infrastructure

The Services run on reputable cloud infrastructure with redundancy across multiple availability zones, automated backups, and continuous monitoring for availability and integrity.

Access controls

Access to production systems and customer data is restricted on a least-privilege basis, protected by multi-factor authentication, and fully audit-logged. Internal access is reviewed on a regular basis.

Application security

We follow secure development practices, including code review, dependency scanning, and regular testing for common vulnerabilities before changes reach production.

Compliance

Wehealt is built to align with standard healthcare and insurance data-handling requirements. We conduct periodic internal reviews and work with third parties to assess our security posture.

Incident response

We maintain an incident response process to detect, contain, and remediate security events, and to notify affected customers in line with applicable legal requirements.

Responsible disclosure

If you believe you've found a security vulnerability in Wehealt, please report it to [email protected]. We ask that you give us a reasonable opportunity to investigate and address any issue before public disclosure, and we will not pursue legal action against good-faith research conducted under this policy.

Contact us

Questions about this page? Reach us at [email protected].