Weel is trusted by 4,000+ companies spending over $1B a year. Certifications, access controls, encryption and where your money actually sits are all set out below, and backed by the control list published in our Trust Center.
The questions procurement and InfoSec teams ask us most.
Is Weel SOC 2 certified?
Yes. Weel holds SOC 2 Type I and Type II, and ISO 27001:2022 certification. We are audited externally each year, penetration tested at least annually, and monitored continuously by Vanta in between. Current certificates and reports are listed in our Trust Center.
Where is our data stored?
On AWS infrastructure. Your data is protected with 256-bit encryption in transit and at rest, and privileged access to production systems and databases is restricted to authorised users with a business need.
Can we enforce single sign on?
Yes, on Enterprise plans. You can enforce SSO so staff sign in to Weel only through your approved SAML or OIDC identity provider. Every account is unique, permissions are role-based, and access is revoked when someone leaves.
What happens if a card is compromised?
You deactivate and replace that user's cards yourself, immediately. There is no need to wait on support.
Are card transactions protected against fraud?
Unauthorised card transactions are covered under Visa Zero Liability. We also use AI to analyse user behaviour and flag suspicious activity as it happens.
Does Weel store our card details?
Card details are tokenised and held by our banking partner, not stored in Weel. Encryption keys are restricted to authorised users with a business need.
Where are company funds held?
Funds are held securely in trust at an Authorised Deposit Taking Institution (ADI).
What stops access from a stolen or unattended device?
Web sessions time out automatically, so an account left open on an unattended or stolen device does not stay accessible.
Can we control what each card is allowed to be used for?
Yes. Every Weel card is governed by pre-set rules, including merchant category restrictions, daily, monthly or custom limits, role-based permissions, and mandatory receipt capture. Enforcement happens in real time rather than after the fact.
How do we get your security documentation for a review?
Start at our Trust Center. Every control we hold is listed there publicly and kept up to date, across infrastructure, organisational, product, internal and data privacy security. The ISO 27001:2022 certificate and Statement of Applicability, and the SOC 2 Type I and Type II reports, are available there by requesting access.
Will you complete our security questionnaire?
Most questionnaires can be answered from the control list published in our Trust Center. If your review needs something that is not published there, ask your Weel contact and we will work through it with you.
What licence does Weel operate under?
In Australia, financial services are provided by Nium Pty Limited under Australian Financial Services Licence 464627, and Weel Holdings Pty Ltd operates as its authorised representative (AFS Authorised Representative 1269625). In New Zealand they are provided by Nium (New Zealand) Limited (FSP 1006810) and Weel New Zealand Limited (FSP 1009961). Your funds are held in trust at an Authorised Deposit Taking Institution.
Request a demo
A Weel expert will reach out to discuss your needs
Over 60,000+ cardholders in Australia and New Zealand.
4,000+ finance teams trust Weel to close every expense.
The top-rated corporate card platform in the region.