Trust & Security

Security built
into every layer.

Your business data is critical. Here is how we protect it from your browser all the way to the database.

UK GDPR
TLS 1.2+ in transit
AES-256 at rest
EU data residency
Row-level security
TOTP 2FA

How your data flows through WeekOne.

Every request travels through multiple independent security controls before it ever touches your data.

Your Browser

Chrome, Safari, Firefox, Edge

HTTPS · TLS 1.2+

Cloudflare Edge Network

DDoS mitigation · Bot protection · WAF · Global CDN

Layer 1

Next.js Application

Server-side rendering · API routes · Middleware auth guard · Edge functions

Layer 2

Supabase Auth

bcrypt password hashing · JWT session tokens · TOTP 2FA · Invite tokens

Layer 3

PostgreSQL

Row-level security policies · Tenant isolation · AES-256 at rest · Daily backups · PITR

Layer 4

Object Storage

Isolated access-controlled buckets · AES-256 at rest · Malware scanning · Signed URLs only

Layer 5

All data stored and processed in EU-West-1 (Ireland) — within UK GDPR and EU data protection jurisdiction.

What each layer does.

Authentication & Access

  • Secure passwords. All passwords are hashed with bcrypt via Supabase Auth. We never store plaintext credentials.
  • Two-factor authentication (2FA). Time-based OTP (TOTP) 2FA is available to all users and can be enforced at the organisation level.
  • Session management. Sessions expire automatically. Users can view and revoke active sessions from their security settings.
  • Role-based access control. Granular permissions ensure team members only access what they need. Roles can be customised per organisation.
  • Secure invitations. Team invitations use single-use cryptographic tokens that expire after 7 days.

Data Encryption

  • Encryption in transit. All data between your browser and our servers is encrypted with TLS 1.2 or higher.
  • Encryption at rest. Data stored in our database and object storage is encrypted at rest using AES-256.
  • Secure file uploads. Documents and attachments are scanned and stored in isolated, access-controlled storage buckets.

Infrastructure

  • EU data residency. Your data is hosted in the EU (Ireland, eu-west-1), keeping it within GDPR jurisdiction.
  • Row-level security. Database access is enforced at the row level. Your data is isolated from other tenants at the database layer, not just the application layer.
  • Automatic backups. Database backups are taken daily with point-in-time recovery available.
  • DDoS protection. All traffic passes through Cloudflare's global network for DDoS mitigation and bot protection.

Compliance

  • UK GDPR compliant. WeekOne operates in accordance with the UK GDPR and the Data Protection Act 2018.
  • Data processing agreement. We provide a DPA on request for organisations that require one for their own compliance obligations.
  • Audit logs. User actions are logged for audit purposes. Organisation owners can review activity from the activity log.
  • Data deletion. You can request deletion of your account and all associated data at any time.

Vulnerability Disclosure

Found a security issue? Please report it responsibly to security@weekoneapp.com. We acknowledge reports within 24 hours and resolve confirmed issues within 30 days.

Questions about security?

Our team is happy to answer questions from customers and prospects. Reach us at security@weekoneapp.com. We typically reply within one business day.

Last updated: July 2026

Privacy policy