Legal

Security & Responsible Disclosure

Last updated: July 14, 2026

← Back to Legal & Compliance

We take the security of WeeBie seriously, and we welcome reports from security researchers acting in good faith. This policy explains how to report a vulnerability and what you can expect from us.

Reporting a Vulnerability

Please email support@weebie.net with the subject line "Security" and include, where possible:

  • A clear description of the issue and its potential impact;
  • Steps to reproduce, including any proof-of-concept;
  • The affected URL, component, or version; and
  • Your name or handle for acknowledgment, if you would like credit.

Scope

This policy covers weebie.net, demo.weebie.net, and the WeeBie Monitor software. Third-party services we rely on are governed by their own programs and policies.

Safe Harbor

If you make a good-faith effort to comply with this policy during your research, we will consider your research authorized, we will not pursue or support legal action against you for it, and we will work with you to understand and resolve the issue promptly. If legal action is initiated by a third party against you for activity conducted under this policy, we will make this authorization known.

Research Guidelines

To stay within safe harbor, please:

  • Avoid privacy violations, data destruction, and degradation of our services;
  • Only interact with accounts you own or have explicit permission to test;
  • Do not access, modify, or exfiltrate data that is not yours, and stop and report as soon as impact is demonstrated;
  • Do not use social engineering, phishing, or physical attacks; and
  • Give us a reasonable opportunity to remediate before publicly disclosing.

What to Expect

We aim to acknowledge reports within a few business days and to keep you informed as we investigate and remediate. As a small team, we do not currently operate a paid bug-bounty program, but we genuinely appreciate responsible disclosure and are glad to credit researchers who wish to be recognized.

Out of Scope

The following are generally not eligible: volumetric denial-of-service attacks; spam or social-engineering of our staff or users; reports of missing best-practice hardening without a demonstrated vulnerability; and issues that exist solely in third-party services we do not control.

Product Security

WeeBie Monitor is engineered to be run in demanding environments: it supports fully air-gapped deployment, maintains a tamper-evident, hash-chained audit trail, ships with digest-pinned components and an SBOM, and provides signed releases. For product security questions or to request security documentation, contact support@weebie.net.

Compliance & Certifications

WeeBie Media, LLC does not currently hold a SOC 2 report, ISO 27001 certification, or any other third-party security certification or attestation. We state that plainly rather than leaving it to be inferred. We would rather you evaluate us on our architecture and our documentation than on a badge.

Why our architecture answers most of the question. WeeBie Monitor is self-hosted. It runs inside your infrastructure — your VPC, your data center, or fully air-gapped — and your prompts, responses, audit trail, and configuration never transit or rest on WeeBie systems. The software does not phone home: license validation is performed offline against a public key embedded in the product, and outbound network access is denied by default. There is no vendor-side copy of your regulated data to breach, subpoena, or mishandle. For most of what a vendor security review is designed to surface, the answer is that your data never leaves your control in the first place.

What the product provides for your compliance program. WeeBie Monitor generates evidence reports mapped to the SOC 2 Trust Services Criteria, GDPR, the EU AI Act, and the HIPAA Security Rule, drawn from its tamper-evident audit chain — alongside data-governance controls (retention and purge, GDPR erasure, data-residency routing) and detection and redaction of personal and health information. These are evidence reports that support an audit. They are not certifications, and they do not by themselves make any organization compliant. Compliance remains determined by your own controls, policies, and auditor.

Your audit trail is yours to keep. The tamper-evident audit chain is never expired or auto-deleted by the product, on any license tier. The data-governance retention controls above apply to operational records — cost rows, violations, and cached responses — not to the audit log; a GDPR erasure likewise removes a subject’s operational records while retaining their audit entries, so the chain still verifies afterward. Because the log is written to your own database on your own hardware, the only limit on how much history you hold is your own disk. If your regulator requires history to expire, you can opt into a retention window yourself — the default is to keep everything, and no plan or license imposes otherwise.

HIPAA. No government-issued HIPAA certification exists for any vendor or product; any party offering one is selling a private opinion. For self-hosted deployments we do not receive, store, or process protected health information, and so do not act as a business associate. Where an engagement would give us access to PHI — a hands-on installation or a support session, for example — we will execute a Business Associate Agreement before that access takes place.

Our public demo is different. The demonstration environment at demo.weebie.net runs on WeeBie-operated infrastructure and does not carry the data-custody properties described above. Please do not enter production, personal, regulated, or otherwise sensitive data into the demo.

To request security documentation, complete a vendor security questionnaire, arrange an architecture review, or put a Business Associate Agreement in place, contact support@weebie.net. This section is updated if our certification status changes.

Contact Us

Questions about security or this policy can be sent to support@weebie.net, or by mail to WeeBie Media, LLC, Tampa, Florida, United States.