# App hosting & & WeWeb Servers & HIPAA

**URL:** <https://community.weweb.io/t/app-hosting-weweb-servers-hipaa/5089>\
**Category:** Ask us anything\
**Tags:** security, hosting\
**Created:** [October 27, 2023, 11:50am UTC](https://community.weweb.io/t/app-hosting-weweb-servers-hipaa/5089 "2023-10-27T11:50:27Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Alexis](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/alexis/32/13248_2.png) [@Alexis](https://community.weweb.io/u/Alexis)\
**Post date:** [October 27, 2023, 3:51pm UTC](https://community.weweb.io/t/app-hosting-weweb-servers-hipaa/5089/2 "2023-10-27T15:51:15Z")

</div>

Hi, it depends of which plugin and options you’re using.

If you’re toggling the “proxy through server” on a REST request it will be forwarded by our server for exemple.  
If you’re using WeWeb Auth it will also ping our servers.  
If you’re using Airtable we have a microservice to hide your API key so it use our servers.  
If you’re using OpenAI its also a microservice to hide your API key and secure prompt.

Except a couple of exception, anything else is a direct connection between your frontend running in the browser and the connected API without WeWeb as a middleware.

If your application connect with xano, supabase, rest api or graphql you should be fine.

---

_[View the full topic](https://community.weweb.io/t/app-hosting-weweb-servers-hipaa/5089)._
