Security
Built for
institutional trust.
PE firms and portfolio companies share highly sensitive organizational intelligence through Wexler Gray. Our security architecture is designed to match the confidentiality expectations of that audience.
How we protect data
Security by design.
Encrypted in transit and at rest
All data is encrypted in transit using TLS 1.3 and encrypted at rest using AES-256. No participant submission or client data is ever transmitted or stored in plaintext.
Tenant isolation
Every request is authorized against the acting user’s role and organization before any client data is returned, so a PE firm user cannot reach data belonging to another PE firm and portfolio-company users see only their own organization. This authorization is enforced in the application on every read and write; database-level row policies are being rolled out as a second, independent layer behind it. We state the control we operate today rather than the one we are still deploying.
No passwords stored
Authentication uses a passwordless magic link model. We never store passwords. There are no credentials to compromise through phishing or credential stuffing.
Administrative audit log
Administrative actions — account creation and changes, organization and portfolio changes, access grants, and invitations — are recorded with the acting user, timestamp, and action. This is an audit trail of administrative changes, not a record of every page a user viewed; we would rather state the narrower control we operate than the broader one we do not. Log-retention terms are set in the engagement agreement.
Role-based access
Platform access is governed by a fixed set of roles — the PE firm’s operating team, portfolio-company leadership (which sees board-ready direction, never raw Signal), and Wexler Gray staff who operate and support the platform. Each role sees only the data its function requires. Wexler Gray staff can access client data to run and support a program; those actions fall under the administrative audit log. Signal participants submit through single-purpose links and hold no platform access. Roles are assigned by Wexler Gray and cannot be self-elevated.
Anonymized submission model
Signal participant submissions carry function labels only, never participant identifiers, and any optional free-text is stripped of obvious identifiers before it is displayed. Individual submissions are never exposed to the portfolio company or to other participants, and nothing surfaces until a pattern recurs, corroborates across functions, and persists. Per-function detail is withheld until a minimum number of people in that function have taken part.
Infrastructure
Enterprise-grade foundations.
The Wexler Gray platform runs on Supabase-hosted PostgreSQL infrastructure, providing a managed, enterprise-grade database with built-in support for row-level security and automated backups. The application layer is deployed via Vercel, providing isolated edge network delivery, automatic TLS, and DDoS mitigation. Both providers maintain SOC 2 Type II certification for the infrastructure they operate.
Wexler Gray builds on that certified infrastructure but does not itself hold an independent SOC 2 certification. Where a client's diligence requires a formal security review, we support that review as part of enterprise onboarding. We describe our controls plainly here rather than implying a certification we do not hold.
Client isolation is enforced in the application: every read and write is checked against the acting user's role and organization before any data is returned, so one client cannot reach another's data. Database-level row policies are being deployed as a second, independent layer behind that check. We describe the control we operate today rather than the defense-in-depth we are still completing.
Authentication is handled via Supabase Auth. Access tokens are short-lived and scoped to the authenticated user's role and organization. Magic links expire after a single use. Sessions are invalidated on sign-out and subject to automatic expiry after a configurable inactivity period.
Signal data isolation
Anonymization is technical, not procedural.
Signal participants submit independently, with no visibility of other participants' submissions. This is not simply a workflow rule — the platform stores no participant identity to join a submission to, submissions are read back de-identified to function labels, and per-function detail is suppressed until a minimum number of people in that function have taken part. Nothing is surfaced until a pattern recurs, corroborates across functions, and persists.
Portfolio company users have read access to synthesised outputs and Bearing interpretations only where explicitly granted by the instructing PE firm. They have no access to individual participant submissions, participant identities, or unaggregated data at any point.
PE firm users have access to all data within their portfolio scope and no access to data outside it. Cross-portfolio data is visible only to PE firm users with explicit cross-portfolio permissions, assigned by Wexler Gray.
Management visibility
Who sees what is decided before the engagement begins.
Signal is commissioned and governed by the investor. Raw submissions and participant identities are never exposed. Visibility into validated themes is controlled through an agreed escalation protocol established at the start of the engagement.
Emerging and developing patterns remain investor-side unless the governance protocol explicitly provides otherwise. Delivery of a validated finding to a portfolio company CEO or board is available only where authorized by the commissioning client. Legal, safety, or misconduct concerns are handled through a separate, predefined escalation path rather than the ordinary theme flow.
Subprocessors and AI processing
Named providers, no model training on your data.
The platform is operated on a small number of infrastructure providers — database and authentication, application delivery, transactional email — each named on our subprocessors page and disclosed to clients under the engagement agreement. We do not sell data, and we do not share client or participant data with third parties outside the subprocessors required to deliver the service.
Signal uses AI to cluster themes, detect recurring and contradictory patterns, and draft explanations. This processing runs through a commercial AI provider whose API terms do not permit using submitted data to train its models. Material and urgent escalations, and all board-facing interpretation, are reviewed by a person before they are relied upon. AI does not independently make employment decisions or determine individual culpability.
Responsible disclosure
If you have identified a potential security vulnerability in the Wexler Gray platform, we ask that you report it privately to allow us to investigate and remediate before any public disclosure.
Report it through the contact form. We respond to all credible reports within 48 hours.