Security
Last updated: July 2026
Wehealt handles sensitive claims and coverage data on behalf of insurers, advisors, and the people they serve. Security is built into the platform at every layer, from infrastructure to day-to-day operations.
Encryption
Data is encrypted in transit using TLS and at rest using industry-standard encryption. Encryption keys are managed separately from the data they protect.
Infrastructure
The Services run on reputable cloud infrastructure with redundancy across multiple availability zones, automated backups, and continuous monitoring for availability and integrity.
Access controls
Access to production systems and customer data is restricted on a least-privilege basis, protected by multi-factor authentication, and fully audit-logged. Internal access is reviewed on a regular basis.
Application security
We follow secure development practices, including code review, dependency scanning, and regular testing for common vulnerabilities before changes reach production.
Compliance
Wehealt is built to align with standard healthcare and insurance data-handling requirements. We conduct periodic internal reviews and work with third parties to assess our security posture.
Incident response
We maintain an incident response process to detect, contain, and remediate security events, and to notify affected customers in line with applicable legal requirements.
Responsible disclosure
If you believe you've found a security vulnerability in Wehealt, please report it tosecurity@wehealt.com. We ask that you give us a reasonable opportunity to investigate and address any issue before public disclosure, and we will not pursue legal action against good-faith research conducted under this policy.
Contact us
Questions about this page? Reach us at support@wehealt.com.

