Weissr Capex · Technology & Trust

The architecture, security and integrations your enterprise review will ask for.

Weissr Capex is a multi-tenant SaaS platform on AWS, ISO 27001 certified, GDPR-compliant, with global data residency, an on-premises option, single sign-on, full audit logging, and an open integration model. Designed so your IT team, security team, and finance leadership can all say yes.

ISO 27001 Certified
GDPR DPA available for signing
99.99% Monthly uptime SLA
Global Any AWS region · on-prem option
Pen tested Annually + on every major release
For your role

The technology decision at a capital-intensive enterprise is never made by one person.

Here is what each of them is really asking, and what Weissr means for them.

CIO / IT Director

You own the vendor security review. You need this to pass — and pass cleanly, on the first submission. Weissr is built to make that happen.

What this means for you
ISO 27001 certificate, pen test summary, DPA: dispatched within one business day under NDA
SAML 2.0 / OIDC SSO with SCIM provisioning: connects to your IdP without custom development
SaaS, single-tenant or on-premises: whichever your deployment policy requires
Full audit log exportable to your SIEM. Every user action, approval and data change recorded

CFO / Finance Leadership

You are approving a long-term technology investment. You need to know the vendor is credible, the data is secure, and the platform will still be running in five years, with an audit trail that satisfies your board and your regulators.

What this means for you
ISO 27001 certified, pen tested annually. A vendor that takes security seriously enough to prove it
Full audit trail on every change: actor, timestamp, value before and after. Every decision documented and traceable
99.99% uptime SLA with service credits, backed by a written service commitment
Named onboarding team, 1–4 month implementation. Predictable investment with a clear timeline

Group Controller / CapEx Team

You will live in this system every day. You need to know it will work without raising IT tickets, that onboarding new entities is straightforward, and that the process survives when people leave.

What this means for you
Business users configure approval workflows, routing and forms. Your team owns the process, IT is not in the loop
New entity or market? Onboarded in days using existing templates, with the same governance from day one
Named onboarding team configures Weissr to your process.
1–4 month implementation with a dedicated team. You know what you are signing up for
01 · Architecture

Architecture & Performance

AWS-hosted SaaS, on-prem option, modern browsers, continuous delivery.

02 · AI

AI Capabilities

Data analysis, forecasting, decision augmentation, and an MCP connector for your own agents.

03 · Security

Security & Compliance

ISO 27001, GDPR, encryption end-to-end, SAML SSO, SCIM, RBAC, audit logging.

04 · Operations

Operations & Support

99.99% uptime, automatic updates, status page, named onboarding team.

01 · Architecture

One platform. Your data. Where your policy requires it.

Weissr Capex runs as a multi-tenant SaaS on Amazon Web Services. Tenants are logically isolated, data encrypted at rest and in transit, and your tenant can be provisioned in any AWS region your organisation requires. For organisations whose policy rules out cloud, single-tenant and on-premises are first-class deployment options: same product, same updates.

  • SaaS, single-tenant or on-premisesDeploy the way your security review allows. No compromise on features.
  • Global data residencyChoose any AWS region at provisioning. Data does not leave the chosen region, ever.
  • Scales across sites and entitiesWorks across 20 production plants in 8 countries, with the same process and governance. Acquired a new entity? Add it in days, not months.
  • Business users as administratorsFinance teams can configure approval workflows, forms and routing without raising an IT ticket. The process is owned by the business.
  • Continuous deliveryAutomatic, zero-downtime updates. New features and security patches without IT effort or scheduled maintenance windows.
  • Modern browsers onlyLatest Chrome, Edge, Firefox, Safari. No client install. Mobile-responsive.

How Weissr Capex connects to your stack

SOURCES ERP systems SAP · Oracle · IFS Identity (IdP) Azure AD · Okta · OneLogin EAM / CMMS Assets · depreciation FX providers Daily rate refresh Procurement POs · committed spend WEISSR CAPEX Capex Strategy Capital Budgeting Capex Management One asset base AWS · ISO 27001 · GDPR CONSUMERS Web browser All modern browsers BI / Reporting Power BI · Tableau · Qlik REST API Webhooks · MCP Excel / Reports Export · SFTP ERP (outbound) Approved projects
TLS 1.2+ in transit Authenticated via your IdP Every action audit-logged
Integration technology

Weissr Capex connects to your stack via standards-based identity (SAML 2.0 / OIDC, SCIM 2.0) and a versioned REST API plus webhooks. Three native SAP S/4HANA connectors. Pre-built patterns for Oracle, IFS, and more.

View all integrations →
02 · AI Capabilities

AI built into the platform — and open to yours.

Weissr applies AI where it makes capex decisions faster and better: surfacing insights from your data, forecasting outcomes, augmenting day-to-day workflows. AI that works inside your capex process, and open to your own agents through an MCP connector.

Data analysis

Ask Weissr to explain a portfolio, find investments off-strategy, compare scenarios or summarise a budget cycle in plain language. Output is always traceable to the underlying data.

Forecasting

AI-assisted forecasts for project costs, cash phasing and portfolio outcomes, using your own historical data, with confidence intervals and assumptions made visible.

Decision augmentation

AI assists capex teams in their actual workflow, drafting business-case narratives, suggesting risks, flagging projects that drift from strategy, summarising review packs. Humans stay in the loop on every decision.

AI governance: your data stays yours

Customer data is never used to train cross-tenant models. Every AI action runs inside your tenant, with the same role-based access controls and audit logging as a human user. Every retrieval is logged: actor, input, output.

New · MCP Connector

Your own AI agents can plug in too.

Weissr exposes its data through the open Model Context Protocol (MCP). Any AI agent or assistant, including Claude, ChatGPT-style copilots, or your internal tooling, can connect and retrieve capex data on demand. Same RBAC as a human user. Every retrieval audit-logged. No custom integration code required.

MCP details →
03 · Security & Compliance

Built to clear enterprise security review on the first pass.

ISO 27001 certified, GDPR-compliant, encryption end-to-end, role-based access control, and an audit trail on every meaningful action. Here is the checklist.

Identity & Compliance
ISO 27001
Certified
+
Certificate available under NDA via the Trust Documents section below.
GDPR
Compliant
+
DPA available for signing. Sub-processor list published and subscribers notified before changes.
Single sign-on (SSO)
SAML 2.0 / OIDC
+
Azure AD / Entra ID, Okta, Google Workspace, ADFS and other SAML/OIDC identity providers supported.
User provisioning
SCIM 2.0
+
Automated user lifecycle management from your IdP. Just-in-time provisioning supported. Joiners, movers and leavers handled without manual admin.
Multi-factor authentication
Enforced
+
Inherited from your IdP, or enforced natively when SSO is not in use.
Role-based access control
Granular
+
Roles and permissions configurable down to module and entity level. Business users manage their own workflows without IT dependency.
Audit logging
Full
+
Every action logged with actor, timestamp, before/after values. Nobody changes a number without a record. Retention configurable. Export to your SIEM.
SOC 2 Type II
In progress
+
Audit underway. Letter of engagement available on request.
Infrastructure & Security
Encryption in transit
TLS 1.2+
+
HTTPS enforced across all endpoints. Modern cipher suites. HSTS enabled.
Encryption at rest
AES-256
+
Tenant data, backups and logs encrypted at rest. Customer-managed keys (BYOK) available on Enterprise tier.
Penetration testing
Annual + on release
+
Independent third-party tests annually and at every major release. Executive summary available under NDA.
Vulnerability management
Continuous
+
Continuous scanning, dependency monitoring, defined SLA for remediation by severity.
Backup & recovery
RPO 1h · RTO 4h
+
Encrypted backups across AWS availability zones. DR runbooks tested annually.
Data residency
Global
+
Provisioned in any AWS region your organisation requires. Data stays in region.
Deployment options
SaaS · On-prem
+
Multi-tenant SaaS, single-tenant, or on-premises installation. Same product, same update cadence across all three.
AI governance
Audit-logged
+
Every AI action runs inside your tenant with the same RBAC and audit logging as a human user. Customer data is never used to train models that benefit other tenants.
MCP connector
Standards-based
+
Open Model Context Protocol endpoint. Authenticated via your IdP. Per-retrieval audit log with actor, input and result.

Need a specific control framework not listed? Talk to our security team →

04 · Operations & Support

Run by people. Monitored by machines. Available when you need it.

Concrete service-level commitments, transparent incident communication, and a named onboarding team that gets your process live on time.

99.99%

Monthly uptime SLA

Multi-AZ deployment on AWS. Service credits if we miss.

RPO 1h · RTO 4h

Disaster recovery

Continuous backups across availability zones. DR runbooks tested annually. You get the results.

1–4 months

Implementation time

Named onboarding team configures workflows, forms and integrations to your process.

24/7

Status & monitoring

Public status page, real-time alerts, named incident contacts on Enterprise. GDPR 72-hour breach notification met.

"Software that owns the capital allocation process has to clear enterprise security review. Weissr does that — ISO certified, integrated with the ERP and EAM systems we already run, and the team responds to our security questions within days."
CIOGlobal Pulp & Paper Group
"Weissr's implementation process was smooth, and they have met all of our IT security requirements. The fact that it's a cloud solution with strong data security measures has been a huge benefit for us, especially when handling highly confidential financial data."
IT ManagerEuropean Energy Corporation
FAQ

What the security and finance leadership ask first.

Where is our data stored?

You choose any AWS region at provisioning, anywhere AWS operates a data centre globally. Your tenant and its backups stay within the chosen region. For organisations whose policy or regulation rules out cloud, single-tenant and on-premises deployments are first-class options with the same product and the same update cadence.

Are you ISO 27001 certified? Do you have a SOC 2 report?

Yes, Weissr is ISO 27001 certified and the certificate is available under NDA via the Trust Documents section. SOC 2 Type II audit is currently in progress; the letter of engagement is available on request.

What identity providers do you support?

SAML 2.0 and OpenID Connect, including Azure AD / Entra ID, Okta, Google Workspace, ADFS, Ping and any other compliant SAML/OIDC provider. SCIM 2.0 for automated user lifecycle management. MFA is enforced, either inherited from your IdP or applied natively when SSO is not in use.

How does Weissr Capex integrate with our existing systems?

Weissr connects to your IdP via SAML or OIDC, provisions users via SCIM, and exposes a versioned REST API and webhooks. Three native SAP S/4HANA connectors are available, along with pre-built patterns for Oracle, IFS and others. Full details on the Integrations page →

How does the audit trail work — and can we export it?

Every user action, approval decision, data change and admin event is logged with actor, timestamp, and before/after values where applicable. Retention is configurable. Logs can be exported directly to your SIEM.

What AI capabilities are built in, and how are they governed?

Weissr provides AI-based functionality for data analysis, forecasting and decision augmentation, and exposes an MCP connector so your own AI agents and assistants can connect to the platform. All AI actions run inside your tenant, against your data, with the same role-based access controls and audit logging as a human user. Every AI retrieval is logged with actor, input and result. Customer data is never used to train models that benefit other tenants.

What is the MCP connector?

The MCP connector exposes Weissr Capex data through the open Model Context Protocol standard. Any AI agent or assistant, including Claude, ChatGPT-style copilots, BI tools, or bespoke internal applications, can connect and retrieve capex data on demand. Authentication runs through your IdP, the same RBAC applies as for human users, and every retrieval is audit-logged. No custom integration code required.

What is your incident response process?

Public status page for real-time service health. Real-time monitoring and alerting on our infrastructure. Named incident contacts on Enterprise tier. Post-incident reviews shared with affected customers. Security incident notifications meet GDPR's 72-hour requirement.

Can we deploy on-premises?

Yes. On-premises is a first-class deployment option in Weissr Capex. You receive the same product, the same features, and the same update cadence as cloud-hosted customers. Our implementation team handles the setup.

How long does implementation take?

End-to-end implementation typically takes 1–4 months depending on the complexity of your integration environment and the number of entities or workflows to configure. A named onboarding team works directly with your team, configuring Weissr to your process.

Talk to our security team.

Skip the marketing call. Bring your questionnaire and we will work through it line by line, with the people who actually run our infrastructure and security programme.

Book a security review →