Chat with us, powered by LiveChat
weAudit Security Certified

Client Data Protection

How We Keep Your Data Safe

weAudit is committed to the highest standards of data security, confidentiality, and trust at every stage of your engagement.

Infrastructure certified under SOC 2 Type II SOC 3 Type II ISO/IEC 27001 PCI-DSS CSA STAR Level 1

When you share your merchant processing statements with weAudit, you are placing significant trust in our hands. That trust is something we take seriously — not just as a contractual obligation, but as a reflection of who we are and how we operate.

Robert Day, CEO & Founder weAudit — America’s #1 Credit Card Processing Auditing Firm

Data Handling

weAudit collects and retains only the information necessary to perform the audit engagement — including merchant processing statements, fee schedules, and audit findings. weAudit does not store, transmit, or retain any cardholder data, payment card numbers, or sensitive authentication data belonging to Client or Client’s customers.

Access Controls

Access to Client audit data is strictly limited to weAudit’s Chief Executive Officer, Vice President of Operations, and the auditor assigned to Client’s account. No other weAudit personnel, contractors, or third parties are granted access to Client-specific data without Client’s prior written consent.

Infrastructure Security

All Client data is hosted on DigitalOcean’s enterprise cloud infrastructure. Under the industry-standard Shared Responsibility Model, weAudit clients benefit from DigitalOcean’s certified security foundation. All data is transmitted exclusively over HTTPS-encrypted connections, and role-based authentication is required for all internal system access.

SOC 2 Type II SOC 3 Type II ISO/IEC 27001 PCI-DSS CSA STAR Level 1 Global CBPR

MADR Technology & Proprietary Systems

weAudit utilizes MADR (Mass Analysis Data Reporting), its proprietary, in-house developed auditing technology, to perform analysis and generate findings. MADR operates exclusively on weAudit’s secured infrastructure, does not transmit Client data to external platforms or third-party services, and is subject to the same access controls and confidentiality obligations described throughout this policy.

No Third-Party Disclosure

weAudit will not sell, license, share, or disclose Client data to any third party for any purpose — including marketing, benchmarking, or research — without the express written consent of Client. This obligation survives the termination of the engagement agreement.

Data Retention

weAudit retains Client audit data for a period of three (3) years following the conclusion of the engagement, after which data is securely archived or deleted. Clients may request deletion of their data at any time by submitting a written request to weAudit’s principal office. weAudit will confirm completion of any deletion request within thirty (30) business days.

Security Incidents

In the unlikely event of an unauthorized access or data breach affecting Client data, weAudit will notify Client in writing within seventy-two (72) hours of discovery and will cooperate fully in any remediation efforts.

Limitation

The security commitments on this page apply solely to data in weAudit’s custody and control. weAudit is not responsible for the security of data transmitted by Client through unsecured channels or stored on Client’s own systems.