Security
Security at Weavely
Last updated: June 2026
Weavely connects your agency's marketing data — Google Ads, Meta, Amazon Ads and dozens of other platforms — directly into your own Google BigQuery, so you can report on it in Looker Studio, Tableau, Power BI and the tools you already use.
The most important fact about Weavely's security model follows from that architecture: your marketing data lives in your Google Cloud project, not ours. We move data into infrastructure you already own and control. We never build a copy of your data on our side to resell access to, and there's no Weavely-owned data lake holding your clients' campaign performance, conversion events or customer identifiers. That single design choice removes an entire category of risk before any policy or certificate enters the picture.
This page describes how Weavely is built and operated today, and where our security program is headed. We believe in telling you what is true now rather than what sounds impressive — if a control isn't listed here, assume we haven't built it yet, and ask us.
How the architecture protects you
Weavely is a data pipeline, not a data warehouse. Here's what that means concretely:
Your data stays in your BigQuery. Ingested data lands in datasets inside your own Google Cloud project. It inherits your project's IAM, your residency, your encryption configuration and your audit logging. You can revoke our access at any time from your own Google Cloud console.
You control residency through Google Cloud. Because the data lives in your BigQuery, you choose its location — US multi-region, EU multi-region,
europe-west1(Belgium),europe-west3(Frankfurt) or any other BigQuery region. Weavely does not relocate it. This is how we serve UK, US, EU and German clients without operating regional data centers of our own: Google Cloud's residency guarantees are yours directly.Least-privilege connection. Weavely requests only the access needed to write the data you've selected into your warehouse, and only the OAuth scopes needed to read the metrics you've chosen from each ad platform. You can review and revoke both connector permissions and our BigQuery access independently.
We don't sell or train on your data. Weavely does not sell, rent or share your data, and does not use it to train machine-learning models. Your data is used solely to deliver the service to you.
Encryption
In transit. All traffic between your browser, our connectors, our APIs, the ad platforms and your warehouse is encrypted with TLS 1.2 or higher. We disable legacy protocols.
At rest, in your warehouse. Data stored in your BigQuery is encrypted at rest by Google Cloud using AES-256 by default. If you configure customer-managed encryption keys (CMEK) on your BigQuery datasets, that protection extends to Weavely-ingested data automatically — including the ability to revoke key access and render the data unreadable. This is configured on your side, in Cloud KMS.
At rest, on our side. The limited operational data Weavely does hold — account settings, connector configuration, pipeline metadata — is encrypted at rest by our cloud provider.
Credentials and secrets
Connecting Weavely involves OAuth tokens and service-account credentials for the ad platforms and for your BigQuery. We:
store these in a dedicated secrets manager, never in source code or configuration files;
request the minimum scope each integration needs;
give you the ability to rotate or revoke any connection from your dashboard at any time.
We are in the process of formalizing a rotation schedule and automated revocation on offboarding; today, revocation is available on request and self-serve from the connector settings.
Access controls
For your team. Weavely provides role-based access so you can scope who in your agency can configure connectors, run pipelines and manage billing. Multi-factor authentication is available on your account today.
SAML single sign-on and SCIM provisioning are on our roadmap, not yet available — if these are requirements for your agency, tell us, because customer demand is how we prioritize.
For Weavely staff. We operate on a least-privilege basis: team members get only the access their role requires. Because your marketing data lives in your BigQuery rather than ours, Weavely staff do not have standing access to it — access to a customer's project is granted only with your authorization, for a specific support purpose. We are working toward formal just-in-time access workflows and access logging as we grow; today these controls are enforced through process rather than fully automated tooling, and we'd rather you know that than assume otherwise.
Application security and development
Code changes are reviewed by a second engineer before they reach production.
We monitor our open-source dependencies for known vulnerabilities and patch them on a prioritized basis.
Production, staging and development environments are kept separate, and we do not use real customer data in development.
We have not yet engaged a third-party penetration test or launched a bug bounty program. Both are planned as the team and customer base grow. We'd rather not claim a pentest report we can't produce.
Privacy, GDPR and international transfers
Weavely Ltd is a UK company, and we take our role under UK GDPR and EU GDPR seriously. Acting as a data processor on your behalf:
Our Data Processing Agreement is incorporated into our Terms of Service and applies to all customers, incorporating the UK International Data Transfer Addendum and the EU Standard Contractual Clauses where data transfers require them. We can also provide a signed copy on request.
Data residency is yours to choose through your BigQuery region (see above), which is the cleanest way to keep EU client data in the EU — for example by provisioning datasets in
europe-west3(Frankfurt).We maintain a subprocessor list and will tell you who we rely on (principally Google Cloud) on request. We'll give you advance notice of material changes.
Data subject requests. Because the data sits in your warehouse under your control, you can action access, correction and deletion requests directly; we'll support you where the request touches Weavely-held configuration.
CCPA/CPRA. For your US clients, Weavely acts as a "service provider" and does not sell or share personal information.
If you have healthcare clients and need a Business Associate Agreement under HIPAA, talk to us about what's feasible — we won't pretend it's a checkbox today.
Data deletion and retention
When you delete a connector or close your account, we stop ingesting and remove Weavely-held configuration and metadata. Data already written into your BigQuery is yours — it remains under your control and you delete it on your own schedule, since it never left your project. We can provide written confirmation of the removal of Weavely-side data on request.
Monitoring and incident response
We monitor our production systems for availability and errors, and our cloud provider's tooling alerts us to anomalous activity. We maintain an internal process for responding to incidents.
In the event of a confirmed security incident affecting your data, we will notify you without undue delay and, where the incident falls under GDPR Article 33 and our DPA, no later than 72 hours after we become aware. Notification will describe what happened, what data was involved, what we've done and who to contact.
We are formalizing this into a documented Incident Response Plan with defined severity levels and post-incident reviews as part of our security roadmap.
Where we're headed
We're a focused team and we prioritize security investment against what our customers actually need. On our roadmap:
SOC 2 Type II and/or ISO 27001 — we hold neither today and will say so plainly until we do;
SAML SSO and SCIM provisioning;
Independent third-party penetration testing;
Formalized just-in-time production access and access logging;
A documented, tested incident response and disaster recovery program.
If one of these is a blocker for your agency, that's exactly the signal that moves it up the list — email us.
Reporting a vulnerability
If you believe you've found a security issue in Weavely, please email security@weavely.com. We ask that you give us reasonable time to respond before any public disclosure, don't access data beyond what's needed to demonstrate the issue, and avoid anything that could degrade service for other customers. We'll acknowledge your report and keep you updated through to resolution, and we won't pursue action against researchers acting in good faith.
Contact
Security questions and vulnerability reports: security@weavely.com
Privacy and data subject requests: privacy@weavely.com
Status and incidents: status.weavely.com
Weavely Ltd · 71–75 Shelton Street, London, WC2H 9JQ, United Kingdom
Own your marketing data. Scale without limits.