Hi everyone and the WeWeb team!
I am writing because both we and our customers have security concerns regarding the WeWeb platform. First, we absolutely love WeWeb and enjoy building apps with it a great deal!
However, one major concern we have is that WeWeb does not provide specific details on how our API tokens are stored and secured within their infrastructure. We use Supabase, and to utilize the Supabase Auth Plugin, we need to store the service_role key in WeWeb. This key grants access to all data stored in the specific Supabase project. WeWebâs Data Processing Agreement for Supabase states, âWeWeb does not store any data passing through this plugin except when using the cached mode. Plugin setup and API tokens are stored on AWS.â This means they store the service_role key in an AWS cluster in the US, but there is no information on how it is protected.
- Is it encrypted end to end?
- Can the WeWeb team view my key in plaintext? If so, how do you ensure that we are not exposed to the threat of disgruntled employees, social engineering, simple mistakes, etc.?
- How do you protect our data from potential leaks on your end?
Perhaps someone from the team could provide some insights?
Thank you very much,
Max