Built to be
examined.

Most automation platforms ask you to trust them. This one is designed so that you do not have to.

Your infrastructure, single-tenant
Your infrastructure
Execution
No vendor cloud in the execution path
01 / 03

Your infrastructure, single-tenant

ProcessWeave is installed on hardware you control — your datacentre, or your own cloud account. One deployment serves one customer. There is no shared control plane, no multi-tenant database, and no path by which your process data reaches us. Data residency is a property of where you installed it, not a promise in a contract.

Your directory decides who is who

Authentication runs against your identity provider over SSO. Roles, approver pools and task assignment resolve from your own directory and master data. ProcessWeave does not maintain a parallel set of user accounts, and does not become a second place where leavers have to be removed.

Credentials never enter a workflow

Components declare the secrets they need in their manifest and receive them scoped, at execution, inside the worker process. Credentials are never written into a workflow definition, and never passed as a step input — because step inputs are persisted in execution history, and a credential in history is a credential you cannot recall.

What the record contains

Human

Human actions

Approvals and rejections, every field edit with its value before and after, remarks, manual-entry submissions, and task claims — each with a verified identity attached.

Automated

Automated actions

Every extraction and model-derived output, with its inputs, the model used, the output produced, the confidence returned, and the decision the reviewing human made.

System

System actions

Every write to an external system, with the identity of the payload and the outcome, plus retries and escalations.

Append-only · Insert-only

And the record cannot be edited

Append-only here means the service writing the log holds INSERT and nothing else — no UPDATE, no DELETE. Migrations run under a separate credential that the running services do not have. Each service checks its own privileges at startup and refuses to serve if it holds more than it should.

AI proposes. Humans dispose.

There is no path from a model to your production systems. AI drafts, a human approves, and only then does anything act. Document extraction returns a confidence score for every field, and anything below your threshold goes to a person instead of becoming a guess.

AI drafts
Human approves
System acts
No path from a model to production.

What is not there yet

We would rather list these than have you find them in a security review.

Per-component permission enforcement

Components declare the permissions they claim today; the platform does not yet enforce them. Enforcement is sequenced with the plugin SDK, because it only becomes meaningful once third-party components exist.

Tamper-evidence

The audit trail is append-only by privilege but is not yet hash-chained or written to WORM storage.

SIEM export

Available on request as a direct read; not yet a supported integration.

Configurable retention policy

Retention is currently a deployment decision rather than a product feature.