Deployment and security
Your infrastructure.
Your choice.
Wevo - the management reporting layer over the General Ledger you already run - runs where your finance data already lives - your cloud, a hybrid arrangement, or entirely on your own premises. Every model has the complete feature set, and none of them ties you to a particular database vendor.
Wevo has no live connection to your General Ledger. It receives files on a schedule and runs entirely outside your GL environment - no access to your database, no effect on its performance, and nothing leaving your boundary.
Cloud
Your cloud account
Deployed into your own AWS, Azure or Google Cloud account. You control the region, the scaling and when it updates.
- Runs under your account, in your region
- Scales with your data volumes
- Your existing cloud controls apply
Hybrid
Data in, application out
Your GL data and database stay on your own infrastructure; the application runs in your cloud account. The usual choice where data residency has to be demonstrated.
- Data never leaves your boundary
- Application tier managed in the cloud
- Meets most residency policies
On-premise
Everything inside
The whole stack within your own walls. Nothing calls out - no licence check, no telemetry, no cloud dependency of any kind.
- Complete data sovereignty
- Runs air-gapped if required
- Suited to banks and government
The boundary changes. The product does not.
Every capability - drill-down, consolidation, email reporting, structure preservation, the source code, both environments - is present in all three models. There is no cut-down edition and nothing is held back for a higher tier.
Security
A baseline, not an option
Because Wevo runs inside your own estate, it inherits the controls you already have. No data crosses an organisational boundary, so the hardest parts of compliance are answered by where it sits rather than by what it promises.
Data stays where it is
Nothing crosses an organisational or geographic boundary outside your estate, which keeps residency requirements straightforward and introduces no transfer agreements.
Your controls, inherited
Permissions, separation of duties and identity provider integration - Azure AD, Okta and the like - are enforced by your own team, in your own security infrastructure.
Everything is logged
Encrypted, time-stamped audit logging covers every data change, structure update and user action, and it is queryable when someone asks.
No third party involved
No cross-border transfers, no external audit obligations, and no third-party data processing agreements are created by deploying Wevo.
No dynamic SQL anywhere
The code base contains none, which removes a whole class of injection risk and makes a security review considerably shorter.
The source code is yours
Supplied in full at installation under a Continuity Licence, so you can keep running the product if vendor support ever ends. Stronger than escrow, and a ready-made exit-strategy document for regulated procurement.