Security

Security at Weblab

Your code, your data, on infrastructure aligned with industry standards.

Your data

Your data, your control

Built to keep what's yours, yours.

GDPR-alignedCCPA-aligned

Encrypted in transit

All traffic is encrypted over TLS. Sessions live in httpOnly, secure cookies.

OAuth sign-in

Sign in with Google or GitHub. No passwords stored. Sessions managed by Supabase.

Code is not used to train AI

Prompts and code are not used to train models. Providers retain logs briefly for abuse detection only.

Open source

Weblab is Apache-2.0 licensed. The full source is on GitHub — audit it, fork it, run it yourself.

Compliance

Compliance posture

We follow the controls behind the standards customers expect.

EU

GDPR-aligned

Data minimization, right to access, right to erasure. Email us to exercise your rights.

California

CCPA-aligned

California residents may opt out of sale or sharing. We do not sell personal data.

ISO 27001

Aligned with ISO 27001 controls

Access control, least-privilege secrets, encryption in transit, and incident response practices.

SOC 2

Modeled on SOC 2 practices

Change management, monitoring, vendor review, and access reviews follow SOC 2 trust criteria.

Apache-2.0

Open-source codebase

Anyone can review our code. Security through transparency, not obscurity.

CVD

Coordinated disclosure

Report vulnerabilities privately via GitHub Security Advisories. We respond within five business days.

Weblab is aligned with these frameworks but is not currently certified against ISO 27001 or SOC 2. Formal audits are on our roadmap.

Vs typical builders

How we compare

Weblab versus typical site builders — where your data stands.

FeatureWeblabTypical site builder
Your codeYours — real React in your Git repoLocked into a proprietary format
Source availableApache-2.0, public on GitHubClosed source
Export your projectAnytime, full sourceRestricted or paid tier
AI training opt-outDefault — your code is never usedOpt-in by default
Open standardsReal Next.js, real PostgresProprietary stack
Region transparencySubprocessors and regions listedOften hidden

Subprocessors

Vendors that process data on our behalf

Every external system that touches customer data, what it does, and where it runs.

NamePurposeRegion
SupabaseAuth + Postgres databaseEU
OpenRouterLLM routing for AI featuresUS
StripePayment processingUS / EU
RailwayApplication hostingUS
GitHubOAuth sign-in + repository syncUS
PostHog*Product analyticsEU
Gleap*User feedback widgetEU
Resend*Transactional emailEU

* Active only when configured. Disabled integrations send no data to that subprocessor.

Last updated 2026-05-12

Contact

Talk to us about security

Questions, compliance reviews, or vulnerability reports — we read every message.

General security questions

Reach out for compliance reviews, DPA requests, or anything else.

Report a vulnerability

Use GitHub Security Advisories for coordinated disclosure. Responses within five business days.

Open a security advisory