Security at Weel

Weel is trusted by 4,000+ companies spending over $1B a year. Certifications, access controls, encryption and where your money actually sits are all set out below, and backed by the control list published in our Trust Center.

4.5 stars
Based on reviews from
A row of logos, including Apple App Store, Google App store, Xero App Store, G2

Join 4,000+ finance teams in Australia and New Zealand completing every expense with Weel.

Control who gets in, what they see, and for how long.

Access & identity
Single sign on. Staff sign in through your approved SAML or OIDC provider, on Enterprise plans.
Role-based access and 2FA. Every account is unique, and people see only what their role allows.
Session timeout. Sessions end on their own, so a stolen or unattended device stays locked out.

If someone leaves or a card is at risk, shut it down in seconds.

Cards & payments
Instant deactivation. Cancel or reissue a card yourself the moment someone leaves or a card is compromised.
Visa Zero Liability on cards. Unauthorised card transactions covered under Visa's policy.
Spend policy rules enforced at the point of purchase. Merchant category, spend limits and receipt capture, applied in real time.

Encrypted in transit and at rest, with your funds held in trust.

Data & funds
256-bit encryption. Your data is encrypted in transit and at rest on AWS infrastructure.
Continuous fraud prevention. AI analyses user behaviour and flags anything suspicious.
Regulated funds storage. Funds held in trust at an Authorised Deposit Taking Institution, under an Australian Financial Services Licence.

Certified by external audit, monitored continuously.

Certifications & compliance
SOC 2 Type I and Type II, and ISO 27001:2022. Audited externally each year and monitored by Vanta in between.
Penetration tested at least annually, with fixes tracked against agreed remediation SLAs.
Every control we hold is listed publicly in the Trust Center, with certificates and audit reports available on request.
SOC 2 Type II and ISO 27001 compliance badges from Vanta

The questions procurement and InfoSec teams ask us most.

Is Weel SOC 2 certified?
Yes. Weel holds SOC 2 Type I and Type II, and ISO 27001:2022 certification. We are audited externally each year, penetration tested at least annually, and monitored continuously by Vanta in between. Current certificates and reports are listed in our Trust Center.
Where is our data stored?
On AWS infrastructure. Your data is protected with 256-bit encryption in transit and at rest, and privileged access to production systems and databases is restricted to authorised users with a business need.
Can we enforce single sign on?
Yes, on Enterprise plans. You can enforce SSO so staff sign in to Weel only through your approved SAML or OIDC identity provider. Every account is unique, permissions are role-based, and access is revoked when someone leaves.
What happens if a card is compromised?
You deactivate and replace that user's cards yourself, immediately. There is no need to wait on support.
Are card transactions protected against fraud?
Unauthorised card transactions are covered under Visa Zero Liability. We also use AI to analyse user behaviour and flag suspicious activity as it happens.
Does Weel store our card details?
Card details are tokenised and held by our banking partner, not stored in Weel. Encryption keys are restricted to authorised users with a business need.
Where are company funds held?
Funds are held securely in trust at an Authorised Deposit Taking Institution (ADI).
What stops access from a stolen or unattended device?
Web sessions time out automatically, so an account left open on an unattended or stolen device does not stay accessible.
Can we control what each card is allowed to be used for?
Yes. Every Weel card is governed by pre-set rules, including merchant category restrictions, daily, monthly or custom limits, role-based permissions, and mandatory receipt capture. Enforcement happens in real time rather than after the fact.
How do we get your security documentation for a review?
Start at our Trust Center. Every control we hold is listed there publicly and kept up to date, across infrastructure, organisational, product, internal and data privacy security. The ISO 27001:2022 certificate and Statement of Applicability, and the SOC 2 Type I and Type II reports, are available there by requesting access.
Will you complete our security questionnaire?
Most questionnaires can be answered from the control list published in our Trust Center. If your review needs something that is not published there, ask your Weel contact and we will work through it with you.
What licence does Weel operate under?
In Australia, financial services are provided by Nium Pty Limited under Australian Financial Services Licence 464627, and Weel Holdings Pty Ltd operates as its authorised representative (AFS Authorised Representative 1269625). In New Zealand they are provided by Nium (New Zealand) Limited (FSP 1006810) and Weel New Zealand Limited (FSP 1009961). Your funds are held in trust at an Authorised Deposit Taking Institution.

Request a demo

A Weel expert will reach out to discuss your needs
Over 60,000+ cardholders in Australia and New Zealand.
4,000+ finance teams trust Weel to close every expense.
The top-rated corporate card platform in the region.
Weel Dashboard