Built to be
boring.
Independent audits, verified uptime and clear custody details — everything your security team needs to sign off on Weir, in one place.
Independently verified. Every quarter.
A third party audits our contracts, custody and controls, and confirms nothing has drifted.
Audit reports. Read the full scope.
Greywall Labs
Smart contract audit · updated March 2026
Solstice Security
Custody & key management · updated March 2026
Anchorline Assurance
SOC 2 Type II · updated March 2026
Bug bounty. Up to $250k.
Scope: smart contracts, custody and the public API. Responsible disclosure only — no automated scanning against production.
Responsible disclosure.
If you find a vulnerability in Weir’s contracts, API or custody path, report it to security@weir.app before you tell anyone else. We reply within one business day and keep you posted while we work the fix.
We ask for a private report, reasonable time to patch before disclosure, and no testing against live customer funds. In return we credit every valid report, pay bounty tiers in full and never pursue legal action against good-faith researchers.
Weir is SOC 2 Type II certified and audited by three independent firms on a rolling basis; every report referenced above is available on request under NDA.
Security, answered.
No. Weir is non-custodial by default — funds move from the payer's wallet to your treasury onchain, and you hold the keys at every step.