Regulatory evidence can contain sensitive industrial, supplier and production information. WEETRA processes client evidence through a controlled Portal architecture hosted in Germany, within the European Union.
Core client evidence is held in the WEETRA Portal hosting environment in Germany. This keeps the primary evidentiary processing environment within the EU.
Files are fingerprinted with SHA-256 during ingestion, enter quarantine, receive malware status and are screened by ClamAV before they become available to the analysis workflow.
Portal access is governed server-side. Sensitive functions use strengthened authentication controls, including MFA where required, together with rate limiting and controlled sessions.
Evidence files, OCR content, case-level facts, detailed findings and reviewer notes remain in the Portal. WEETRA Ops receives only sanitised operational telemetry and opaque references needed for supervision.
WEETRA publishes a privacy framework and Article 28 processing terms covering client instructions, rights, retention, security, sub-processing and data-protection contacts.
WEETRA publishes specific controls that can be evidenced in the current architecture rather than relying on generic security scores or unsupported certification badges.
The Evidence Check produces a shareable PDF that records the reviewed scope, the evidence population, identified documentary relationships, findings and the actions that require attention.