Skip to content
SECURITY AND GOVERNANCE

Security that fits how you deploy Weezie.

Security responsibilities can vary depending on how Weezie is hosted, integrated, and operated. We work with customers to understand the deployment model, define the relevant responsibilities, and identify the technical and operational considerations for their environment.

Secure infrastructure and operational controls for Weezie deployments.
RESPONSIBILITY MODEL

Understand who is responsible for what.

The security model around Weezie depends on the chosen deployment and the systems connected to it. Some responsibilities relate to the Weezie platform itself, while others can depend on hosting arrangements, customer infrastructure, identity providers, integrations, and internal operational processes.

Weezie platform

Security considerations within the Weezie application and the components maintained as part of the product.

Application security

May include: Application behavior, platform permissions, supported authentication mechanisms, and product-level security controls.

Platform evolution

May include: Application updates, dependency changes, fixes, and changes affecting supported functionality.

Product configuration

May include: Roles, permissions, authentication options, integrations, and deployment-specific settings.

Hosting and infrastructure

Infrastructure responsibilities depend on where and how Weezie is deployed.

Deployment environment

May include: Cloud infrastructure, networking, operating systems, databases, storage, backups, and supporting services.

Environment boundaries

May include: Private networks, VPNs, firewall rules, network segmentation, and access restrictions.

Operational access

May include: Infrastructure administration, platform maintenance, support access, and operational procedures.

Customer environment

Customers remain central in determining how people and systems access their own deployment.

Identity and user access

May include: User lifecycle management, identity provider configuration, role assignment, and internal access policies.

Connected systems

May include: API credentials, third-party applications, data pipelines, automation, and system-to-system access.

Data governance

May include: Data classification, retention policies, internal governance, exports, and downstream use of Weezie data.

SECURITY CONSIDERATIONS

Review the areas relevant to your environment.

Rather than assuming one model applies everywhere, we review the areas that matter for each deployment.

Access and identity

Authentication

Review how users and systems authenticate with Weezie. Possible topics include identity providers, application credentials, API authentication, and administrative access.

Authorization

Define how access to platform capabilities and information should be distributed across users and systems. Possible topics include roles, permissions, organizational boundaries, and integration access.

Operations and resilience

Logging and auditing

Determine what operational and application information should be available for troubleshooting, review, or integration with other systems. Possible topics include application activity, authentication events, infrastructure logs, and external monitoring.

Backups and recovery

Define the backup and recovery approach appropriate to the hosting model. Possible topics include backup frequency, retention, infrastructure snapshots, database recovery, and operational responsibilities.

Coordination and integrations

Incident coordination

Define how relevant parties coordinate when investigating a security or operational issue. Responsibilities and communication paths can vary by involved systems and infrastructure.

Integrations and API access

Consider the security implications of systems interacting with Weezie programmatically. Possible topics include credentials, permissions, network access, data flows, and credential lifecycle management.

Network and connectivity

Network access

Determine how Weezie communicates with users, infrastructure, and connected systems. Possible topics include private connectivity, VPNs, firewalls, exposed services, and network architecture.

Encryption

Review encryption requirements appropriate to the deployment and the services involved. Possible topics include transport encryption, storage configuration, certificates, and infrastructure services.

Platform lifecycle

Vulnerability management

Review how vulnerabilities affecting the platform and its dependencies are identified and handled. The process can vary by affected component and deployment model.

Updates and maintenance

Establish how application and infrastructure changes are introduced into the environment. This can include product releases, dependency updates, infrastructure maintenance, and customer-specific deployment procedures.

DEPLOYMENT

Security responsibilities follow the deployment model.

Security responsibilities follow deployment model, infrastructure boundaries, and how connected systems are introduced.

Weezie-managed environments

Where Weezie operates the application environment, more infrastructure and platform operation can remain inside the Weezie operational scope.

Customer-managed environments

For deployments in customer-controlled infrastructure, infrastructure responsibilities can remain primarily with the customer while Weezie supports the application layer.

Connected environments

Most deployments interact with systems beyond Weezie itself, including identity providers, GIS, APIs, reporting pipelines, OSS/BSS, and other operational systems.

Keep access aligned with the way your organization works.

Security is not limited to infrastructure; access and movement across systems needs matching controls.

  • User access: Configure platform access around the roles and responsibilities of teams using Weezie.
  • API access: Align programmatic access with the same roles, segmentation, and purpose as interactive access.
  • Administrative access: Restrict privileged actions to the people and processes responsible for managing the environment.
  • External systems: Include system-to-system integrations when defining authentication, permissions, network access, and data flow.
  • Data movement: Handle exports, reporting pipelines, and integrations as data traverses between environments with different control boundaries.
CUSTOMER REQUIREMENTS

Start with your requirements.

Security requirements vary between organizations, industries, deployment models, and procurement processes.

  • Application architecture
  • Hosting and deployment
  • Authentication and access
  • Roles and permissions
  • Network architecture
  • API security
  • Data storage
  • Backup and recovery
  • Logging and monitoring
  • Platform maintenance
  • Integration architecture
  • Operational responsibilities
  • Data protection considerations
  • Security questionnaires and procurement requirements
Connected operations

Start with the requirements that matter most.

We can work with your technical or security teams to review the areas relevant to a Weezie deployment and provide available information on platform, architecture, and operating model.