Weights & Biases
Weights & Biases is the unified AI development platform for LLMs, AI agents, and machine learning. Fine-tune foundation models, trace agentic workflows, run systematic evaluations, and monitor production systems. Includes model registry, experiment tracking, and serverless reinforcement learning. Enterprise governance controls, audit logging, and on-premise deployment options.
Features
- Unified, agnostic platform for ML, LLM, and Agent development
- Serverless reinforcement learning for AI agent post-training
- Agentic workflow tracing with multi-turn observability and debugging
- LLM and AI agent evaluation with custom scorers
- Guardrails for prompt safety and harmful output blocking
- Advanced tools for AI model research and development
- Central registry for AI version control, lineage, and governance
- Production monitoring for AI quality, latency, cost and drift
- Enterprise security and governance controls, comprehensive audit logging
- Flexible deployment models, including on-premise options
Benefits
- Ship reliable AI agents faster with unified development and evaluation
- Improve AI product quality by systematically evaluating outputs before production
- Train AI agents without infrastructure complexity using serverless Reinforcement Learning
- Debug agentic workflows quickly with full multi-turn trace visibility
- Block harmful AI outputs automatically with configurable guardrails
- Accelerate foundation model fine-tuning with automated experiment tracking
- Ensure reproducibility with versioned models, datasets, and full lineage
- Meet audit requirements with searchable logs and approval workflows
- Reduce AI compute costs with optimised training and resource monitoring
- Maintain control with on-premise and air-gapped deployment options
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 9 4 9 1 8 9 6 4 1 9 2 7 1 2
Contact
XMA LIMITED
Nancy Clayton-Schofield
Telephone: 0115 846 4000
Email: bidteam@xma.co.uk
About your service
- Service categories
-
Application Development and Deployment
AI platforms
AI life cycle
- AI Build Software
- MLOps and Foundation Model Ops Software
- Trustworthy AI Software
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
-
Our SaaS service requires reliable internet connectivity for real time experiment tracking and collaboration features. We schedule maintenance during low-traffic periods with advance notice to minimise operational disruption.
Customer managed deployments of Weights & Biases need Kubernetes compatible infrastructure, and the customer's own technical teams must provision and maintain Server versions.
Python SDK integration requires Python 3.7 or later runtime environments. These requirements align with standard enterprise software practices and ensure optimal platform performance. - System requirements
-
- Kubernetes with ingress and persistent volume support
- MySQL database; performance and storage scale with metadata complexity
- Single-node Redis 7.x for queuing and caching
- Object storage with pre-signed URL and CORS support
- Self-managed Weave deployments rely on ClickHouseDB
- SaaS and Dedicated Cloud deployments are managed by W&B
User support
- Email or online ticketing support
- Yes
- Support response times
-
Support response times vary by plan tier and issue priority:
Standard and Standard Plus Plans:
- Critical (P0): 4 business hours
- High (P1): 12 business hours
- Medium and Low (P2 and P3): 24 business hours
Premium Plan:
- Critical (P0): 1 business hour
- High (P1): 2 business hours
- Medium and Low (P2 and P3): 4 business hours - User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Premium Support guarantees a dedicated Technical Account Team which includes:
An AI Solutions Engineer, who provides: continous technical account management, onsite and virtual user enablement sessions, best practice guidance on feature usage to achieve workflow target outcomes.
A Solutions Architects who: deliver guidance and support for deployment and maintenance at scale.
Support Engineers who: assist via virtual methods including email, Slack, and Teams.
The annual cost for Premium Support is a minimum of $25,000 for W&B Models, and $25,000 for W&B Weave. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- A dedicated W&B account team helps users get started through a combination of onboarding, training, and documentation. They typically provide guided onboarding sessions by an AI Solutions Engineer, architecture and setup guidance by a Solutions Architect, and best practice recommendations tailored to particular use cases. Training is usually delivered remotely via live online workshops or walkthroughs, and may include enablement sessions for engineers, researchers, and administrators. Onsite training can be arranged when required. In addition, users are supported with comprehensive self-serve resources, including detailed online documentation, tutorials, examples, and reference guides. Ongoing support is available through the account team and support channels as adoption grows.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Users can programmatically download runs, metrics, artifacts, and metadata via the W&B APIs and SDKs, or manually export artifacts and reports through the web UI. Artifacts can be retrieved from their underlying storage locations (for example, cloud object storage) if users manage or have access to those backends. For Self-Managed deployments, users retain full access to their infrastructure and databases, allowing complete data export or migration. After contract termination and data retention periods expire, W&B may delete hosted data, so users are responsible for exporting data in advance.
- End-of-contract process
-
At contract end, customers retain full ownership and access to all their data. We provide comprehensive export capabilities through our API, SDK, command-line interface, and web interface. Customers can download all experiment runs, metrics, artifacts, and metadata in standard formats at any time during or at the contract end period.
For organisations using customer-managed storage options, data already resides within their own infrastructure, ensuring complete control throughout the relationship. Self-managed deployments provide direct access to underlying databases and storage backends using standard tools.
Our support team assists with transition planning and data migration as needed. We maintain detailed documentation covering all export procedures. There are no technical barriers to migration, and we do not delete any customer data without explicit request.
We design our platform around open APIs and standard data formats, specifically avoiding proprietary lock-in that would complicate future transitions. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Tbc
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
Teams access Weights & Biases through an intuitive web application requiring no installation or specialist setup. The browser-based interface provides dashboards, experiment tracking, collaborative reports, and project management tools.
Technical users integrate lightweight SDKs into existing Python or other language workflows. These capture metrics, model artifacts, and metadata automatically without disrupting current processes. A command-line interface supports authentication and administrative tasks for platform teams. Open APIs enable integration with existing CI/CD pipelines, data platforms, and ML frameworks.
All interfaces share consistent design patterns, reducing training requirements and enabling teams to become productive within hours. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Interface testing of W&B Models web app UI and core features with a visually impaired user requiring assistive technology
- API
- Yes
- What users can and can't do using the API
-
Service Setup via API: Users can create projects, teams, and workspaces programmatically through our comprehensive REST and Python APIs. Developers can authenticate using API keys and integrate directly with existing CI/CD pipelines and automation workflows. The API supports full experiment tracking setup, including configuring logging parameters, artifact storage, and model registry entries.
Changes via API: Teams can log runs, metrics, artifacts, and metadata throughout the machine learning lifecycle without manual intervention. Users can query experiment data, download artifacts, and export results for integration with other systems. The API enables programmatic report creation, automation configuration, and webhook management for event-driven workflows. Model registry operations including artifact creation, alias assignment, and lineage tracking are fully API accessible.
Limitations: Initial organisation setup and SSO configuration are typically completed through the web interface for streamlined administration. User provisioning via SCIM may require initial UI configuration before API automation takes effect. Complex dashboard customisation and certain advanced visualisations are more easily managed through the interface. Administrative functions including billing management and organisation level settings remain UI-based. Self managed deployment options provide additional API control over infrastructure compared to our SaaS offering. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
What can be customised: Dashboards, visualisations, metrics tracking, automated workflows, reports, team structures, storage backends, authentication methods, and network configurations. Self-managed deployment provides complete infrastructure control.
How users customise: Through an intuitive web interface for visual configuration, APIs and SDKs for programmatic control, YAML configuration files for automation, and Terraform for infrastructure-as-code deployment.
Who can customise: Role-based permissions govern all customisation access. End users configure personal dashboards and reports. Project administrators manage team settings. Organisation administrators control authentication, security policies, and billing. Platform teams customise infrastructure, networking, and storage backends in self-managed deployments.
Scaling
- Independence of resources
-
W&B-managed deployments use logical isolation, scalable infrastructure, and usage controls. This ensures users are not impacted by demand from other users.
Customer data is isolated by organization and workspace. Workloads are handled by horizontally scalable services that automatically adjust to load. Rate limiting and quotas prevent abusive usage from degrading performance.
Enterprise and Self-Managed customers benefit from dedicated or isolated infrastructure. This eliminates cross-tenant impact and ensures consistent performance. Our architecture is designed for high availability with redundant components.
Analytics
- Service usage metrics
- Yes
- Metrics types
- W&B provides users with service usage metrics that help track and manage platform consumption. These include counts of runs, logged metrics, artifacts, and storage usage, as well as data upload and download volumes. Users can also view activity metrics such as active users, project usage, and workspace-level activity. In hosted environments, W&B surfaces usage related to billing and quotas, while Self-Managed deployments can monitor usage through system metrics, logs, and integrations with external monitoring tools.
- Reporting types
-
- API access
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Weights and Biases
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
-
Users can export data from W&B through several supported mechanisms. They can use the W&B APIs and SDKs to download runs, metrics, system logs, and associated metadata
Users can also export models, datasets, and other files through W&B Artifacts. Artifacts can be downloaded via the SDK, the CLI, or directly through the web UI. If artifacts are stored in customer-managed object storage, users may also retrieve the data directly from that underlying storage system.
For Self-Managed deployments, users retain full access to the underlying databases and storage backends, allowing complete data extraction using standard database and storage tools. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- Pandas dataframe
- PDF (W&B Reports)
- Export files stored in their original open file formats
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Pandas DataFrames
- JSON
- Parquet
- Text
- Images (PNG, JPEG)
- Audio
- Video
- HTML
- NumPy Arrays
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection within supplier network
- TBC
Availability and resilience
- Guaranteed availability
-
W&B-Managed Cloud Deployments: Weights & Biases guarantees 99.5% availability per calendar month for our managed cloud service under Enterprise agreements. This contractual commitment equates to a maximum of approximately 3.65 hours unplanned downtime monthly.
SLA Credit Structure: Should availability fall below guaranteed levels, customers receive service credits applied to subsequent invoices:
- Below 99.5%: 10% monthly service credit
- Below 99.0%: 25% monthly service credit
- Below 95.0%: 50% monthly service credit
These credits are contractually binding and automatically calculated based on measured uptime.
Self-Managed Deployments
For organisations deploying W&B within their own infrastructure, availability is determined by your configuration choices. We provide comprehensive guidance on implementing highly available architectures, including redundancy configurations, failover strategies, and backup procedures. Your team maintains full control over uptime commitments aligned with internal service standards. - Approach to resilience
-
Our service architecture aligns with NCSC's Asset Protection and Resilience principle, ensuring continuous availability and data integrity.
Application: Microservices architecture with isolated failure domains enables horizontal scaling and prevents cascading failures. Stateless application tiers facilitate rapid scaling and replacement. Continuous health monitoring triggers automatic recovery, whilst load balancing ensures uninterrupted traffic routing during component failures.
Infrastructure: spans multiple availability zones within each region, eliminating single points of failure. Cloud providers maintain N+1 redundancy for power, cooling, and networking, with SOC 2 and ISO 27001 certified facilities. Geographic distribution enables regional failover capabilities.
Data: Geographically distributed backups with point-in-time recovery safeguard against data loss. Immutable backup storage prevents tampering, whilst automated verification ensures backup integrity. Cross-region replication provides additional protection for critical workloads.
Business Continuity: Documented disaster recovery procedures with defined Recovery Time and Recovery Point Objectives are tested regularly. Automated failover minimises service disruption.
Self-Managed: Customers deploying within their own infrastructure retain full control over resilience architecture. We provide comprehensive guidance for high-availability deployment, with Kubernetes operator support for multi-zone configurations.
Additional detail can be shared under NDA to qualified procurement teams. - Outage reporting
-
Weights & Biases maintains a public status dashboard. The dashboard displays current operational status, historical uptime metrics, and detailed incident timelines - all accessible without authentication, ensuring complete transparency.
Additionally, authorised users can subscribe to automatic alerts through multiple channels:
- Email notifications for incident updates and resolution
- RSS/Atom feeds for integration with existing monitoring workflows
- Webhook support for Slack, Microsoft Teams, and enterprise alerting platforms
Our status API enables your technical teams to integrate service health checks directly into existing monitoring infrastructure, supporting automated alerting and compliance reportingrequirements.
We provide advance notice of scheduled maintenance windows, typically communicated seven or more days beforehand. Maintenance is scheduled during low-usage periods to minimise operational impact.
During unplanned outages, we publish regular status updates throughout the incident lifecycle. Following resolution, we provide post-incident reports detailing root cause analysis and preventive measures implemented.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Other user authentication
-
Users authenticate through multiple methods to access W&B services. We support email and password-based authentication with multi-factor authentication via Okta for enhanced security.
Enterprise customers use Sngle Sign On through SAML 2.0 identity federation, enabling integration with existing providers including Google Apps and other OAuth-based identity providers.
For programmatic access, users authenticate via API keys for SDK, CLI, and automation workflows
Dedicated W&B Managed Cloud and Self-Managed deployments support additional security controls including private networking, IP allow lists, and secure ingress configurations to meet organisational security requirements. - Access restrictions in management interfaces and support channels
-
Management interfaces require authentication via Okta SSO with multi-factor authentication. We enforce role-based access controls with segregation of duties between initiators and approvers for changes.
Administrative access uses identity federation through SAML 2.0 or OAuth-based providers, API keys for programmatic access, and email/password with MFA. All management actions are logged with comprehensive audit trails.
Support channels restrict access to authorised personnel only. Internal support uses dedicated Slack channels with access controls. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Description of management access authentication
- API keys for SDK, CLI, and programmatic management access
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
We are certified under ISO/IEC 27001:2022, ISO/IEC 27017:2015, and ISO/IEC 27018:2019. We remain compliant with SOC 2 Type 2 and HIPAA standards.
Our platform helps customers comply with NIST 800-53. We are aligned with GDPR requirements for processing personal information. - Information security policies and processes
-
Weights & Biases maintains a comprehensive Information Security Management System (ISMS)
aligned with ISO/IEC 27001:2022, comprising 27 formal policies and 20 documented procedures.
Governance and Risk Management:
Our security programme is underpinned by an Information Security Governance Policy, supported
by formal risk management, internal audit procedures, and clearly defined roles and
responsibilities.
Access and Identity Management:
We enforce strict access controls through dedicated Access Control and Management, Password,
and BYOD policies, ensuring principle of least privilege across all systems.
Data Protection and Privacy:
Data Classification and Handling, Backup, and Privacy policies govern information throughout
its lifecycle, supported by documented data deletion and restoration procedures.
Infrastructure and Operations:
Cloud Security, Network Security, Endpoint Protection, and Platform Patch Management policies
protect our technical environment. Vulnerability Management and Penetration Testing ensures
ongoing identification and remediation of security weaknesses.
Business Continuity:
Business Continuity and Disaster Recovery policies, supported by Business Impact Analysis and
tested recovery plans, ensure service resilience.
Secure Development:
Our Software Development Lifecycle policy incorporates security-by-design principles, supported
by documented change management and configuration control procedures.
All policies are formally documented, version-controlled, subject to annual review, and
independently audited as part of our SOC 2 Type II and ISO 27001 certification programmes. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Service components are tracked throughout their lifecycle using infrastructure-as-code via Terraform, version-controlled in Git. Golden Images standardise VM configurations. Wiz provides continuous monitoring and automated drift detection against CIS benchmarks for AWS, Azure, GCP, and Kubernetes platforms. Monthly security reviews ensure compliance.
All changes undergo mandatory risk and impact assessment before implementation. Security team approval is required for platform security changes. Changes are peer-reviewed with segregation of duties between initiator and approver. Testing occurs in non-production environments. Post-implementation monitoring validates security controls remain effective. Emergency changes receive retroactive security review. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
We assess threats through continuous automated scanning of infrastructure, dependencies, source code, and cloud environments using Docker CVE scans, Wiz, SAST tools, Trufflehog, Socket scans. Quarterly third-party penetration testing supplements automated detection. Vulnerabilities are prioritised using CVSS scoring, assessing business impact, exploitability, and compliance obligations.
Patch deployment follows risk-based timelines: Critical vulnerabilities remediated within 30 days, High within 60 days, Medium within 90 days.
Threat intelligence sources include National Vulnerability Database, vendor security advisories, penetration test findings, bug bounty programmes (HackerOne, Bugcrowd), cloud security alerts, and security research communities. All findings are aggregated in Linear for tracking and remediation management. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
We identify potential compromises using RunReveal and Sentinel One to detect security events through continuous monitoring of logs, alerts, and system activity. Multiple detection sources include automated scanning, employee reporting, customer notifications, and bug bounty programmes.
Upon detecting potential compromises, the Security Incident Response Team (SIRT) assembles immediately via private Slack channels. We implement containment and eradication measures as quickly as possible, which may include taking systems offline, removing access, or applying patches.
Employees report incidents immediately to our security inbox. Impacted customers receive notification within 72 hours of confirmed impact. Post-incident reviews occur within one week. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Our incident management follows NIST SP 800-61 Rev. 2 framework with defined playbooks for common scenarios including data breaches, ransomware, and system compromises. Incidents are categorised by severity (P0-P3) with defined response procedures.
Users report incidents to a security inbox. Employees, customers, vendors, and bug bounty programmes serve as detection sources. The Security Incident Response Team triages all reports via private Slack channels.
We provide incident reports to impacted customers within 72 hours of confirmed impact. Post-incident debriefs occur within one week. External communications are issued solely by the CISO or authorised designee. Internal incident documentation remains confidential. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- W&B offers a 30-day free enterprise trial that lets users evaluate core features without committing to a paid plan. Included in the trial are most enterprise capabilities that help teams manage and track ML and GenAI workflows.
- Link to free trial
- Wandb.ai/site
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- LRQA Limited
- ISO/IEC 27001 accreditation date
- Thursday 27 November 2025
- What the ISO/IEC 27001 doesn’t cover
- The certificate scope covers the full company business operations, across all business locations, applicable and relevant to the delivery, deployment and management of IT solutions, support and services in accordance with Statement of Applicability Version 4, and is audit against the new 2022 standard.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- LRQA Limited
- ISO 9001 accreditation date
- Monday 17 February 2025
- What the ISO 9001 doesn’t cover
- The certificate scope covers the full company business operations, across all business locations, applicable and relevant to the Delivery, Deployment and Management of IT Solutions, Support and Services.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- Barclaycard
- PCI DSS accreditation date
- Thursday 9 January 2025
- What the PCI DSS doesn’t cover
- Our PCI DSS certification applies exclusively to payment processing systems and hosted payment gateways and does not extend to non‑payment systems, corporate IT infrastructure, or business applications outside the cardholder data environment.
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- B5f066ef-ff99-48a9-94b0-23f1f0ee595b
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 2d75659c-9df3-4d75-9406-9052a6e68c4b
- Other security certifications
- Yes
- Any other security certifications
- IASME CYBER ASSURANCE LEVEL ONE
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-