Security

Security is a system of responsibilities—not a single product feature.

WMT evaluates identity, authorization, application safeguards, infrastructure, delivery, operations, and incident handling in the context of the applicable solution.

Control areas

Security should be evaluated across the complete solution boundary.

The exact controls and responsible party vary by product, deployment, integration, infrastructure, service, and signed agreement.

01

Identity and access

Authentication, identity sources, roles, permissions, privileged access, account lifecycle, administrative actions, and user responsibility.

  • Role and permission design
  • Administrative access
  • Account provisioning and removal
  • Identity-provider integration where applicable
02

Application and data

Secure application behavior, validation, authorization, session handling, data access, exports, logging, integrations, and configuration.

  • Authorization at relevant functions
  • Input and output handling
  • Data-flow and integration review
  • Environment-appropriate logging
03

Infrastructure and operations

Hosting boundary, network and platform controls, secrets, patching, monitoring, backup responsibilities, support access, and operational change.

  • Environment ownership
  • Platform and dependency maintenance
  • Operational access and monitoring
  • Backup and recovery responsibilities

Secure delivery

Security decisions should appear throughout the lifecycle.

Security is weakened when it is treated only as a final checklist. Discovery, design, build, integration, migration, deployment, training, support, and change all contribute.

No universal control claim: a public summary cannot establish that every control exists in every product, version, deployment, or customer environment. Confirm the applicable architecture and agreement.
  1. Discover risk and data

    Identify users, roles, data categories, integrations, environments, threats, legal constraints, and business impact.

  2. Design the boundary

    Define identity, authorization, interfaces, hosting, secrets, logging, backups, access, and responsibility.

  3. Build and validate

    Apply relevant engineering controls, reviews, testing, configuration checks, integration tests, and acceptance evidence.

  4. Operate and improve

    Manage access, monitoring, maintenance, support, incident routing, approved change, and lifecycle updates.

Customer context

Security depends on controls outside WMT as well.

The customer’s identity systems, devices, networks, administrators, data handling, connected platforms, and operating procedures remain part of the risk model.

Customer identity and users User verification, account ownership, role approval, credential protection, timely removal, endpoint security, and acceptable use.
Customer infrastructure Where customer-managed, network, server, operating system, database, backup, monitoring, and administrative controls remain customer responsibilities.
Connected systems Identity providers, SIS/ERP platforms, email, payment, storage, analytics, and other third parties introduce their own controls and dependencies.
Operational procedures Approval, segregation of duties, data export, report distribution, incident escalation, support authorization, and change governance.

Security contact

Report responsibly and through the appropriate channel.

Do not use a public form to send credentials, personal data, customer records, exploit code, or sensitive vulnerability detail.

Security file

Published reporting information

The website security file provides the current public security-contact route and disclosure guidance.

Open security.txt

Existing customer

Use Support

For an existing environment, use the established support and escalation process so the affected product and customer context are known.

Contact Support

Evaluation

Use Contact Sales

Route due-diligence questionnaires, architecture questions, and proposed security terms through the commercial evaluation process.

Contact Sales

General

Contact WMT

Use the general contact route when the correct commercial, project, or support owner is not yet known.

Contact WMT

Questions

Frequently asked questions

Does WMT claim a specific security certification on this page?

No. This page does not claim ISO, SOC, PCI, government, or other certification. Any certification or independent-assurance claim must be supported by a current authoritative document.

How is user access controlled?

WMT products support product-appropriate identity, authentication, roles, permissions, and administrative controls. Exact capabilities, identity integrations, configuration, and customer responsibilities vary by product and deployment.

Are data encrypted?

Encryption requirements and implementation depend on the product, deployment, infrastructure, interface, and agreement. They should be confirmed in the applicable technical and contractual documentation rather than assumed from a general website statement.

How are vulnerabilities and updates handled?

Secure development, dependency management, testing, release, patching, and operational responsibilities should be defined for the applicable product and service. Exact timelines and coverage require confirmation.

How should a security concern be reported?

Use the published security contact in the site security file or the established Support channel for an existing customer. Do not include exploit details or sensitive data in a public form.

Security in context

Confirm the product, deployment, data, integrations, and evidence required.

The right answer depends on the applicable solution and relationship—not a generic control list.