Security
Weeka security controls.
This page describes controls visible in the current system, shared responsibilities, and limits that still require verification.
Regulatory status: Weeka does not currently claim HIPAA compliance and does not offer a verified Business Associate Agreement (BAA). Until those controls and agreements are confirmed in writing, do not use Weeka to store or transmit protected health information (PHI).
Account and session
Passwords are protected with BCrypt. Google sign-in validates the identifier, application audience, and verified email. Sessions use signed tokens; the refresh token is delivered in an HttpOnly, Secure cookie in production, rotates when renewed, and is stored as a hash on the server.
Weeka applies a configurable inactivity timeout and allows password changes from the profile.
Authorization and access separation
The API requires authentication for private routes. Workspaces include owner, admin, planner, and worker roles, along with membership states and calendar permissions. Administrative functions require an administrator role.
Public note links use unique tokens, an expiration date, a disable option, and request limits. The person creating a link remains responsible for distributing it.
Application protection
The public deployment uses HTTPS and headers including HSTS, Content Security Policy, X-Content-Type-Options, framing protection, a restrictive referrer policy, and disabled camera, microphone, and geolocation permissions.
Request limits cover sign-in, registration, verification, invitations, public links, and billing operations. Stripe webhook signatures are validated before events are processed.
Providers and infrastructure
Current operations may rely on Railway and PostgreSQL for the application and data, Cloudflare for delivery and network protection, Stripe for payments, Google for optional sign-in, and Resend or SMTP for email. Each provider maintains its own controls and terms.
Production secrets are supplied through environment variables; database, Stripe, and token-signing keys are not included in client-side code.
User responsibility
Use a unique password, protect the associated email account, regularly review members and roles, revoke access that is no longer appropriate, and verify recipients before sharing notes or reports.
Do not enter regulated or unnecessary data without first confirming that the contractual, technical, and organizational requirements for your use case are in place.
Report a possible issue
If you notice unexpected access, an exposed link, abnormal behavior, or a vulnerability, stop sharing affected material, revoke access when possible, and contact an official channel. Do not publish exploitable details or include sensitive data in the first message.
Official Weeka information
This page will be updated when the product’s practices, providers, or controls change.