Security & Compliance

How we handle your data.

Last reviewed: April 24, 2026. Everything on this page is updated as our posture matures. If a procurement reviewer needs a specific document that is not linked here, email security@wexplo.ai.

Overview

Wexplo is operated by A. O. Signtech (company registration no. 513915652, Israel) and runs on a modern cloud stack with encryption in transit and at rest, tenant-scoped row-level security at the database layer, and per-customer audit trails on content changes. Visitor-facing audio guides at wexplo.ai/g/* are public by design; all other data (creator accounts, site editors, analytics, billing) is tenant-isolated.

We are in the first year of the B2B product. Rather than claim certifications we do not have, this page is transparent about current posture and timeline to the next milestone. If that level of maturity does not meet your institution's threshold today, we would prefer to know now: email security@wexplo.ai.

Compliance & certifications

In progress

SOC 2 Type I

Scoping in Q2 2026. Report targeted for Q4 2026. Annual Type II thereafter.

Compliant

GDPR (EU / UK)

Data controller: A. O. Signtech. DPA available under NDA on request.

Compliant

EAA (European Accessibility Act)

Every visitor stop ships with audio + full transcript + photo alt text in all 14 languages. Meets the June 2025 obligations for EU cultural institutions.

Compliant

ADA / WCAG 2.1 AA

Visitor player tested against WCAG 2.1 AA. Transcript-read paths, keyboard navigation, screen-reader labels on every control.

On request

ISO 27001

Not certified today. We pair with institutions that require ISO 27001 by mapping their controls to our existing posture in a vendor-risk review.

Not applicable

HIPAA / PCI-DSS

We do not store protected health information. Payment card data is handled exclusively by our merchant-of-record (Paddle), not by Wexplo.

Data handling & encryption

  • In transit: TLS 1.2+ everywhere. HSTS on wexplo.ai with a preload marker. All storage URLs signed and served over HTTPS.
  • At rest: AWS-managed AES-256 encryption for database content and object storage. Database backups encrypted by Supabase with 7-day point-in-time recovery.
  • Tenant isolation: Row-level security policies scope creator content to the owning account. Admin-elevated roles gate cross-tenant access and are limited to the Wexplo operations team.
  • Transient AI content: Text sent to OpenAI / Google / ElevenLabs for TTS or translation is not retained by those providers for training per their business-tier agreements. Generated audio is stored in our own bucket.
  • Secrets: API keys and credentials live in Supabase Edge Function secrets + Vercel environment variables. No credentials are committed to git or present in client-side code.
  • Logs: Access logs, function invocations, and error traces retained 30 days in Supabase + PostHog. Payment transaction logs retained 7 years per tax and audit requirements.

Subprocessors

Wexplo uses the following subprocessors to deliver the service. Material changes are communicated at least 30 days in advance to customers on annual contracts.

SubprocessorPurposeRegion
Supabase (PostgreSQL + Storage + Edge Functions)Primary data store, object storage, backend functionsAWS us-east-1
VercelMarketing site + creator dashboard hostingGlobal edge network
OpenAITTS fallback (gpt-4o-mini-tts); content is transientUS
ElevenLabsMultilingual narration (Multilingual v2); content is transientUS / EU
Google Cloud, Gemini + Cloud TTSTranslation, photo alt-text, Hebrew narration; content is transientGlobal
PaddleMerchant-of-record billing, invoices, tax handlingEU
ResendTransactional email (account, site status notifications)US / EU
PostHogProduct analytics (EU cloud instance)EU

Data Processing Agreement

Our standard Data Processing Agreement is based on the EU SCCs (standard contractual clauses) and is available to customers on Growth, Business, and Enterprise tiers. Email security@wexplo.ai to request a DPA draft; we can countersign within 5 business days on standard terms.

Accessibility

Accessibility is a first-class feature of Wexplo Sites, not an afterthought. Every visitor stop ships with:

  • Narrated audio in all 14 supported languages, with native-accent voices
  • Full transcript automatically generated for every language so deaf and hard-of-hearing visitors get the same content
  • AI-generated photo alt text for every uploaded image, translated into all 14 languages, meeting alt-text requirements under WCAG 2.1 AA 1.1.1
  • Keyboard-accessible player with visible focus states, skip-by-15s controls, and screen-reader-tested ARIA labels
  • Font-size / dark-mode respect, the visitor player honors operating-system text size and color-scheme preferences

This posture meets or exceeds the requirements of the EU European Accessibility Act (EAA) effective June 28, 2025, the Americans with Disabilities Act (ADA) Title III, and WCAG 2.1 Level AA. A full Voluntary Product Accessibility Template (VPAT) is available under NDA on request.

Data residency

Primary data (customer accounts, site content, audio files) lives in AWS us-east-1 via Supabase. For institutions that require EU-resident storage, contact us: a dedicated Supabase project in AWS eu-central-1 is available on Business tier and above at no additional charge. PostHog analytics runs on the EU cloud instance by default.

Authentication & access control

  • Email + password with bcrypt hashing (managed by Supabase Auth, industry-standard cost factor)
  • Email verification required before a creator can publish
  • Session tokens expire after 1 hour and rotate automatically on refresh; revocable on logout or password change
  • Admin review gate on new-site publication (Free tier); paid tiers publish instantly under server-enforced RLS
  • SSO (SAML / OIDC) available on Enterprise tier via Supabase Auth SSO
  • Optional MFA on Enterprise accounts

Incident response

Security incidents are triaged by the Wexplo operations team on discovery or notification. Customer-facing incidents that involve personal data are communicated to affected customers within 72 hours of confirmation, in line with GDPR Article 33. Status and mitigation updates are posted on a public status page (rolling out with SOC 2 Type I in Q4 2026). Report a suspected incident at security@wexplo.ai; we acknowledge within 1 business day.

Security contact

One inbox, one human. We reply to procurement and security requests within 1 business day, including for vendor-risk questionnaires, DPA redlines, VPAT requests, subprocessor questions, and incident reports.

Email: security@wexplo.ai