Security & Architecture

Technical assurance for verifiable communication

WSD SaaS

We Secure Data SaaS is hosted and operated by We Secure Data. Messages and files are encrypted in the browser before storage, with organisation boundaries, identity-based access, audit records and cryptographic provenance built into the workflow.

Starter, Professional and Business customers use the managed SaaS service without provisioning their own cloud project, KMS or dedicated infrastructure.

Encryption icon
Client-side encryption

Messages and files are encrypted before upload, reducing readable-data exposure inside vendor infrastructure.

Separation icon
Organisation separation

Identity-based access and organisation security boundaries keep each tenant’s users and content separated within the hosted service.

Audit icon
Access, audit and provenance

Controlled external access, audit context and cryptographic provenance help teams verify the recorded sender identity and whether a document changed.

Threat model

What We Secure Data is designed to reduce.

Designed to protect against
  • Vendor breach exposing readable customer data.

  • Unauthorised direct access to encrypted content in storage.

  • SaaS central breach target risk.

  • Storage compromise where attackers obtain encrypted blobs only.

Not designed to replace
  • Endpoint security for compromised user devices.

  • Strong identity controls for stolen user credentials.

  • Good internal access governance, approvals, and user lifecycle management.

Implementation-backed cryptography

Browser encryption and independently reproducible evidence checks.

Files use AES-256-GCM with fresh per-file data-encryption keys, authenticated chunk metadata and KMS key wrapping. Separate ECDSA P-256 keys sign canonical provenance evidence and public audit anchors.

A trusted public key must first be obtained from the authenticated WSD key endpoint or another trusted source.

Read the Cryptographic Protocol
Separate deployment model

WSD Dedicated Deployment

Need your own infrastructure?

Organisations that want their own environment can purchase a turnkey dedicated deployment. WSD prepares the agreed environment, ready for the customer to take ownership. The scope can include dedicated infrastructure, customer-controlled KMS and IAM, and an organisation-specific domain and branding.

This is a premium alternative to SaaS, not a prerequisite for using We Secure Data.