Built to be
boring.

Independent audits, verified uptime and clear custody details — everything your security team needs to sign off on Weir, in one place.

Your keys · non-custodial
Your keys · non-custodial

Independently verified. Every quarter.

A third party audits our contracts, custody and controls, and confirms nothing has drifted.

#01

SOC 2 Type II

Compliance

Controls tested over months, not on a single day.

#01

SOC 2 Type II

Compliance

Controls tested over months, not on a single day.

#02

3 audits

Independent audits

Contracts, custody and controls, each by a separate firm.

#02

3 audits

Independent audits

Contracts, custody and controls, each by a separate firm.

#03

99.99 %

Uptime

Measured over the trailing 12 months.

#03

99.99 %

Uptime

Measured over the trailing 12 months.

#04

<400 ms

Median quote

Median time to quote a settlement.

#04

<400 ms

Median quote

Median time to quote a settlement.

#05

0.2 %

Failed-settlement rate

Share of transfers that fail to settle.

#05

0.2 %

Failed-settlement rate

Share of transfers that fail to settle.

#06

Non-custodial

Custody

By default, Weir never holds your keys.

#06

Non-custodial

Custody

By default, Weir never holds your keys.

Audit reports. Read the full scope.

Greywall Labs

Smart contract audit · updated March 2026

Solstice Security

Custody & key management · updated March 2026

Anchorline Assurance

SOC 2 Type II · updated March 2026

Bug bounty. Up to $250k.

#01

$250,000

Critical

Paid in full for a valid critical report.

#01

$250,000

Critical

Paid in full for a valid critical report.

#02

$50,000

High

For high-severity findings in scope.

#02

$50,000

High

For high-severity findings in scope.

#03

$10,000

Medium

For medium-severity findings in scope.

#03

$10,000

Medium

For medium-severity findings in scope.

Scope: smart contracts, custody and the public API. Responsible disclosure only — no automated scanning against production.

Responsible disclosure.

If you find a vulnerability in Weir’s contracts, API or custody path, report it to security@weir.app before you tell anyone else. We reply within one business day and keep you posted while we work the fix.

We ask for a private report, reasonable time to patch before disclosure, and no testing against live customer funds. In return we credit every valid report, pay bounty tiers in full and never pursue legal action against good-faith researchers.

Weir is SOC 2 Type II certified and audited by three independent firms on a rolling basis; every report referenced above is available on request under NDA.

Security, answered.

No. Weir is non-custodial by default — funds move from the payer's wallet to your treasury onchain, and you hold the keys at every step.

Ready to pass your next audit.

Create a free website with Framer, the website builder loved by startups, designers and agencies.