Last updated: July 2026
Wehealt handles sensitive claims and coverage data on behalf of insurers, advisors, and the people they serve. Security is built into the platform at every layer, from infrastructure to day-to-day operations.
Data is encrypted in transit using TLS and at rest using industry-standard encryption. Encryption keys are managed separately from the data they protect.
The Services run on reputable cloud infrastructure with redundancy across multiple availability zones, automated backups, and continuous monitoring for availability and integrity.
Access to production systems and customer data is restricted on a least-privilege basis, protected by multi-factor authentication, and fully audit-logged. Internal access is reviewed on a regular basis.
We follow secure development practices, including code review, dependency scanning, and regular testing for common vulnerabilities before changes reach production.
Wehealt is built to align with standard healthcare and insurance data-handling requirements. We conduct periodic internal reviews and work with third parties to assess our security posture.
We maintain an incident response process to detect, contain, and remediate security events, and to notify affected customers in line with applicable legal requirements.
If you believe you've found a security vulnerability in Wehealt, please report it to [email protected]. We ask that you give us a reasonable opportunity to investigate and address any issue before public disclosure, and we will not pursue legal action against good-faith research conducted under this policy.
Questions about this page? Reach us at [email protected].