Server aisle inside a data center

Company

Weaver Is SOC 2 Type 2 Certified

Capital project data is among the most sensitive information in enterprise operations. Construction programs generate cost forecasts, subcontractor performance records, safety incidents, contractual disputes, and proprietary design documents — data that owners and contractors treat as confidential, and that regulators in sectors like life sciences and semiconductors treat as a compliance matter in its own right.

We take that responsibility seriously. Today, we're announcing that Weaver has completed its SOC 2 Type 2 audit.

What SOC 2 Type 2 means — and why Type 2 is different

SOC 2 is a security framework developed by the American Institute of Certified Public Accountants that evaluates whether a company's systems and controls adequately protect the data entrusted to it. It covers five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.

The distinction between Type 1 and Type 2 matters. A Type 1 audit is a point-in-time assessment — it verifies that controls are designed correctly at a specific moment. Type 2 is more demanding: it evaluates whether those controls actually operated effectively over an extended period. An auditor reviews logs, tests controls, and verifies that the security posture described in the report reflects how the system has actually behaved over time.

A Type 2 certification isn't a snapshot. It's evidence that the controls work in practice, not just on paper.

Why this matters for capital project owners and GCs

The programs Weaver serves — data centers, semiconductor fabrication facilities, life sciences facilities — operate in environments where data governance is not optional. Owner organizations in these sectors are themselves subject to stringent compliance requirements: SOX, HIPAA, export controls, and industry-specific regulatory frameworks. When they bring a third-party platform into their program, they're extending their data governance perimeter. They need confidence that the platform meets the same standards they're held to.

SOC 2 Type 2 is the benchmark procurement teams, IT security organizations, and legal counsel use to evaluate that question. Having it removes friction from the enterprise procurement process and, more importantly, gives owner teams an independently verified basis for confidence in how their project data is handled.

For GCs, the story is similar. Project data — subcontractor agreements, cost forecasts, change order documentation — is sensitive commercial information. SOC 2 Type 2 confirms that the controls governing access, transmission, storage, and availability of that data have been tested and verified, not just described.

What the audit covered

Our SOC 2 Type 2 certification covers the Security and Availability Trust Services Criteria. The audit examined access controls and authentication mechanisms across the Weaver platform, encryption of data in transit and at rest, monitoring and incident response procedures, change management and system availability controls, and vendor and subprocessor management.

Building on a foundation of trust

Weaver was built to give owners and GCs independent visibility into their programs. That visibility only means something if the platform handling the data can be trusted.

SOC 2 Type 2 is one component of that trust — alongside the contractual protections in our customer agreements, our data handling practices, and the design principles that govern what data we collect and how it's used. We'll continue to build on it as Weaver expands to new program types and customer environments.

For questions about our security practices or to request a copy of our SOC 2 report, contact security@helloweaver.com.

Ask Weaver
Capital project intelligence