Skip to main content

Help us improve the Digital Marketplace - send your feedback

XMA LIMITED

Weights & Biases

Weights & Biases is the unified AI development platform for LLMs, AI agents, and machine learning. Fine-tune foundation models, trace agentic workflows, run systematic evaluations, and monitor production systems. Includes model registry, experiment tracking, and serverless reinforcement learning. Enterprise governance controls, audit logging, and on-premise deployment options.

Features

  • Unified, agnostic platform for ML, LLM, and Agent development
  • Serverless reinforcement learning for AI agent post-training
  • Agentic workflow tracing with multi-turn observability and debugging
  • LLM and AI agent evaluation with custom scorers
  • Guardrails for prompt safety and harmful output blocking
  • Advanced tools for AI model research and development
  • Central registry for AI version control, lineage, and governance
  • Production monitoring for AI quality, latency, cost and drift
  • Enterprise security and governance controls, comprehensive audit logging
  • Flexible deployment models, including on-premise options

Benefits

  • Ship reliable AI agents faster with unified development and evaluation
  • Improve AI product quality by systematically evaluating outputs before production
  • Train AI agents without infrastructure complexity using serverless Reinforcement Learning
  • Debug agentic workflows quickly with full multi-turn trace visibility
  • Block harmful AI outputs automatically with configurable guardrails
  • Accelerate foundation model fine-tuning with automated experiment tracking
  • Ensure reproducibility with versioned models, datasets, and full lineage
  • Meet audit requirements with searchable logs and approval workflows
  • Reduce AI compute costs with optimised training and resource monitoring
  • Maintain control with on-premise and air-gapped deployment options

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bidteam@xma.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 9 4 9 1 8 9 6 4 1 9 2 7 1 2

Contact

XMA LIMITED Nancy Clayton-Schofield
Telephone: 0115 846 4000
Email: bidteam@xma.co.uk

About your service

Service categories

Application Development and Deployment

AI platforms

AI life cycle

  • AI Build Software
  • MLOps and Foundation Model Ops Software
  • Trustworthy AI Software
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
  • Hybrid cloud
Service constraints
Our SaaS service requires reliable internet connectivity for real time experiment tracking and collaboration features. We schedule maintenance during low-traffic periods with advance notice to minimise operational disruption.

Customer managed deployments of Weights & Biases need Kubernetes compatible infrastructure, and the customer's own technical teams must provision and maintain Server versions.

Python SDK integration requires Python 3.7 or later runtime environments. These requirements align with standard enterprise software practices and ensure optimal platform performance.
System requirements
  • Kubernetes with ingress and persistent volume support
  • MySQL database; performance and storage scale with metadata complexity
  • Single-node Redis 7.x for queuing and caching
  • Object storage with pre-signed URL and CORS support
  • Self-managed Weave deployments rely on ClickHouseDB
  • SaaS and Dedicated Cloud deployments are managed by W&B

User support

Email or online ticketing support
Yes
Support response times
Support response times vary by plan tier and issue priority:

Standard and Standard Plus Plans:
- Critical (P0): 4 business hours
- High (P1): 12 business hours
- Medium and Low (P2 and P3): 24 business hours

Premium Plan:
- Critical (P0): 1 business hour
- High (P1): 2 business hours
- Medium and Low (P2 and P3): 4 business hours
User can manage status and priority of support tickets
No
Phone support
No
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Premium Support guarantees a dedicated Technical Account Team which includes:
An AI Solutions Engineer, who provides: continous technical account management, onsite and virtual user enablement sessions, best practice guidance on feature usage to achieve workflow target outcomes.
A Solutions Architects who: deliver guidance and support for deployment and maintenance at scale.
Support Engineers who: assist via virtual methods including email, Slack, and Teams.
The annual cost for Premium Support is a minimum of $25,000 for W&B Models, and $25,000 for W&B Weave.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
A dedicated W&B account team helps users get started through a combination of onboarding, training, and documentation. They typically provide guided onboarding sessions by an AI Solutions Engineer, architecture and setup guidance by a Solutions Architect, and best practice recommendations tailored to particular use cases. Training is usually delivered remotely via live online workshops or walkthroughs, and may include enablement sessions for engineers, researchers, and administrators. Onsite training can be arranged when required. In addition, users are supported with comprehensive self-serve resources, including detailed online documentation, tutorials, examples, and reference guides. Ongoing support is available through the account team and support channels as adoption grows.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Users can programmatically download runs, metrics, artifacts, and metadata via the W&B APIs and SDKs, or manually export artifacts and reports through the web UI. Artifacts can be retrieved from their underlying storage locations (for example, cloud object storage) if users manage or have access to those backends. For Self-Managed deployments, users retain full access to their infrastructure and databases, allowing complete data export or migration. After contract termination and data retention periods expire, W&B may delete hosted data, so users are responsible for exporting data in advance.
End-of-contract process
At contract end, customers retain full ownership and access to all their data. We provide comprehensive export capabilities through our API, SDK, command-line interface, and web interface. Customers can download all experiment runs, metrics, artifacts, and metadata in standard formats at any time during or at the contract end period.

For organisations using customer-managed storage options, data already resides within their own infrastructure, ensuring complete control throughout the relationship. Self-managed deployments provide direct access to underlying databases and storage backends using standard tools.

Our support team assists with transition planning and data migration as needed. We maintain detailed documentation covering all export procedures. There are no technical barriers to migration, and we do not delete any customer data without explicit request.

We design our platform around open APIs and standard data formats, specifically avoiding proprietary lock-in that would complicate future transitions.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Tbc

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Teams access Weights & Biases through an intuitive web application requiring no installation or specialist setup. The browser-based interface provides dashboards, experiment tracking, collaborative reports, and project management tools.

Technical users integrate lightweight SDKs into existing Python or other language workflows. These capture metrics, model artifacts, and metadata automatically without disrupting current processes. A command-line interface supports authentication and administrative tasks for platform teams. Open APIs enable integration with existing CI/CD pipelines, data platforms, and ML frameworks.

All interfaces share consistent design patterns, reducing training requirements and enabling teams to become productive within hours.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Interface testing of W&B Models web app UI and core features with a visually impaired user requiring assistive technology
API
Yes
What users can and can't do using the API
Service Setup via API: Users can create projects, teams, and workspaces programmatically through our comprehensive REST and Python APIs. Developers can authenticate using API keys and integrate directly with existing CI/CD pipelines and automation workflows. The API supports full experiment tracking setup, including configuring logging parameters, artifact storage, and model registry entries.

Changes via API: Teams can log runs, metrics, artifacts, and metadata throughout the machine learning lifecycle without manual intervention. Users can query experiment data, download artifacts, and export results for integration with other systems. The API enables programmatic report creation, automation configuration, and webhook management for event-driven workflows. Model registry operations including artifact creation, alias assignment, and lineage tracking are fully API accessible.

Limitations: Initial organisation setup and SSO configuration are typically completed through the web interface for streamlined administration. User provisioning via SCIM may require initial UI configuration before API automation takes effect. Complex dashboard customisation and certain advanced visualisations are more easily managed through the interface. Administrative functions including billing management and organisation level settings remain UI-based. Self managed deployment options provide additional API control over infrastructure compared to our SaaS offering.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
What can be customised: Dashboards, visualisations, metrics tracking, automated workflows, reports, team structures, storage backends, authentication methods, and network configurations. Self-managed deployment provides complete infrastructure control.

How users customise: Through an intuitive web interface for visual configuration, APIs and SDKs for programmatic control, YAML configuration files for automation, and Terraform for infrastructure-as-code deployment.

Who can customise: Role-based permissions govern all customisation access. End users configure personal dashboards and reports. Project administrators manage team settings. Organisation administrators control authentication, security policies, and billing. Platform teams customise infrastructure, networking, and storage backends in self-managed deployments.

Scaling

Independence of resources
W&B-managed deployments use logical isolation, scalable infrastructure, and usage controls. This ensures users are not impacted by demand from other users.

Customer data is isolated by organization and workspace. Workloads are handled by horizontally scalable services that automatically adjust to load. Rate limiting and quotas prevent abusive usage from degrading performance.

Enterprise and Self-Managed customers benefit from dedicated or isolated infrastructure. This eliminates cross-tenant impact and ensures consistent performance. Our architecture is designed for high availability with redundant components.

Analytics

Service usage metrics
Yes
Metrics types
W&B provides users with service usage metrics that help track and manage platform consumption. These include counts of runs, logged metrics, artifacts, and storage usage, as well as data upload and download volumes. Users can also view activity metrics such as active users, project usage, and workspace-level activity. In hosted environments, W&B surfaces usage related to billing and quotas, while Self-Managed deployments can monitor usage through system metrics, logs, and integrations with external monitoring tools.
Reporting types
  • API access
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Weights and Biases

Staff security

Staff security clearance
Other security clearance
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Users can export data from W&B through several supported mechanisms. They can use the W&B APIs and SDKs to download runs, metrics, system logs, and associated metadata

Users can also export models, datasets, and other files through W&B Artifacts. Artifacts can be downloaded via the SDK, the CLI, or directly through the web UI. If artifacts are stored in customer-managed object storage, users may also retrieve the data directly from that underlying storage system.

For Self-Managed deployments, users retain full access to the underlying databases and storage backends, allowing complete data extraction using standard database and storage tools.
Data export formats
  • CSV
  • Other
Other data export formats
  • Pandas dataframe
  • PDF (W&B Reports)
  • Export files stored in their original open file formats
Data import formats
  • CSV
  • Other
Other data import formats
  • Pandas DataFrames
  • JSON
  • Parquet
  • Text
  • Images (PNG, JPEG)
  • Audio
  • Video
  • HTML
  • NumPy Arrays

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection within supplier network
TBC

Availability and resilience

Guaranteed availability
W&B-Managed Cloud Deployments: Weights & Biases guarantees 99.5% availability per calendar month for our managed cloud service under Enterprise agreements. This contractual commitment equates to a maximum of approximately 3.65 hours unplanned downtime monthly.

SLA Credit Structure: Should availability fall below guaranteed levels, customers receive service credits applied to subsequent invoices:
- Below 99.5%: 10% monthly service credit
- Below 99.0%: 25% monthly service credit
- Below 95.0%: 50% monthly service credit
These credits are contractually binding and automatically calculated based on measured uptime.

Self-Managed Deployments
For organisations deploying W&B within their own infrastructure, availability is determined by your configuration choices. We provide comprehensive guidance on implementing highly available architectures, including redundancy configurations, failover strategies, and backup procedures. Your team maintains full control over uptime commitments aligned with internal service standards.
Approach to resilience
Our service architecture aligns with NCSC's Asset Protection and Resilience principle, ensuring continuous availability and data integrity.

Application: Microservices architecture with isolated failure domains enables horizontal scaling and prevents cascading failures. Stateless application tiers facilitate rapid scaling and replacement. Continuous health monitoring triggers automatic recovery, whilst load balancing ensures uninterrupted traffic routing during component failures.

Infrastructure: spans multiple availability zones within each region, eliminating single points of failure. Cloud providers maintain N+1 redundancy for power, cooling, and networking, with SOC 2 and ISO 27001 certified facilities. Geographic distribution enables regional failover capabilities.

Data: Geographically distributed backups with point-in-time recovery safeguard against data loss. Immutable backup storage prevents tampering, whilst automated verification ensures backup integrity. Cross-region replication provides additional protection for critical workloads.

Business Continuity: Documented disaster recovery procedures with defined Recovery Time and Recovery Point Objectives are tested regularly. Automated failover minimises service disruption.

Self-Managed: Customers deploying within their own infrastructure retain full control over resilience architecture. We provide comprehensive guidance for high-availability deployment, with Kubernetes operator support for multi-zone configurations.

Additional detail can be shared under NDA to qualified procurement teams.
Outage reporting
Weights & Biases maintains a public status dashboard. The dashboard displays current operational status, historical uptime metrics, and detailed incident timelines - all accessible without authentication, ensuring complete transparency.

Additionally, authorised users can subscribe to automatic alerts through multiple channels:
- Email notifications for incident updates and resolution
- RSS/Atom feeds for integration with existing monitoring workflows
- Webhook support for Slack, Microsoft Teams, and enterprise alerting platforms

Our status API enables your technical teams to integrate service health checks directly into existing monitoring infrastructure, supporting automated alerting and compliance reportingrequirements.

We provide advance notice of scheduled maintenance windows, typically communicated seven or more days beforehand. Maintenance is scheduled during low-usage periods to minimise operational impact.

During unplanned outages, we publish regular status updates throughout the incident lifecycle. Following resolution, we provide post-incident reports detailing root cause analysis and preventive measures implemented.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Other user authentication
Users authenticate through multiple methods to access W&B services. We support email and password-based authentication with multi-factor authentication via Okta for enhanced security.

Enterprise customers use Sngle Sign On through SAML 2.0 identity federation, enabling integration with existing providers including Google Apps and other OAuth-based identity providers.

For programmatic access, users authenticate via API keys for SDK, CLI, and automation workflows

Dedicated W&B Managed Cloud and Self-Managed deployments support additional security controls including private networking, IP allow lists, and secure ingress configurations to meet organisational security requirements.
Access restrictions in management interfaces and support channels
Management interfaces require authentication via Okta SSO with multi-factor authentication. We enforce role-based access controls with segregation of duties between initiators and approvers for changes.

Administrative access uses identity federation through SAML 2.0 or OAuth-based providers, API keys for programmatic access, and email/password with MFA. All management actions are logged with comprehensive audit trails.

Support channels restrict access to authorised personnel only. Internal support uses dedicated Slack channels with access controls.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Description of management access authentication
API keys for SDK, CLI, and programmatic management access

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
No audit information available
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
We are certified under ISO/IEC 27001:2022, ISO/IEC 27017:2015, and ISO/IEC 27018:2019. We remain compliant with SOC 2 Type 2 and HIPAA standards.

Our platform helps customers comply with NIST 800-53. We are aligned with GDPR requirements for processing personal information.
Information security policies and processes
Weights & Biases maintains a comprehensive Information Security Management System (ISMS)
aligned with ISO/IEC 27001:2022, comprising 27 formal policies and 20 documented procedures.

Governance and Risk Management:
Our security programme is underpinned by an Information Security Governance Policy, supported
by formal risk management, internal audit procedures, and clearly defined roles and
responsibilities.

Access and Identity Management:
We enforce strict access controls through dedicated Access Control and Management, Password,
and BYOD policies, ensuring principle of least privilege across all systems.

Data Protection and Privacy:
Data Classification and Handling, Backup, and Privacy policies govern information throughout
its lifecycle, supported by documented data deletion and restoration procedures.

Infrastructure and Operations:
Cloud Security, Network Security, Endpoint Protection, and Platform Patch Management policies
protect our technical environment. Vulnerability Management and Penetration Testing ensures
ongoing identification and remediation of security weaknesses.

Business Continuity:
Business Continuity and Disaster Recovery policies, supported by Business Impact Analysis and
tested recovery plans, ensure service resilience.

Secure Development:
Our Software Development Lifecycle policy incorporates security-by-design principles, supported
by documented change management and configuration control procedures.

All policies are formally documented, version-controlled, subject to annual review, and
independently audited as part of our SOC 2 Type II and ISO 27001 certification programmes.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Service components are tracked throughout their lifecycle using infrastructure-as-code via Terraform, version-controlled in Git. Golden Images standardise VM configurations. Wiz provides continuous monitoring and automated drift detection against CIS benchmarks for AWS, Azure, GCP, and Kubernetes platforms. Monthly security reviews ensure compliance.

All changes undergo mandatory risk and impact assessment before implementation. Security team approval is required for platform security changes. Changes are peer-reviewed with segregation of duties between initiator and approver. Testing occurs in non-production environments. Post-implementation monitoring validates security controls remain effective. Emergency changes receive retroactive security review.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
We assess threats through continuous automated scanning of infrastructure, dependencies, source code, and cloud environments using Docker CVE scans, Wiz, SAST tools, Trufflehog, Socket scans. Quarterly third-party penetration testing supplements automated detection. Vulnerabilities are prioritised using CVSS scoring, assessing business impact, exploitability, and compliance obligations.

Patch deployment follows risk-based timelines: Critical vulnerabilities remediated within 30 days, High within 60 days, Medium within 90 days.

Threat intelligence sources include National Vulnerability Database, vendor security advisories, penetration test findings, bug bounty programmes (HackerOne, Bugcrowd), cloud security alerts, and security research communities. All findings are aggregated in Linear for tracking and remediation management.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
We identify potential compromises using RunReveal and Sentinel One to detect security events through continuous monitoring of logs, alerts, and system activity. Multiple detection sources include automated scanning, employee reporting, customer notifications, and bug bounty programmes.

Upon detecting potential compromises, the Security Incident Response Team (SIRT) assembles immediately via private Slack channels. We implement containment and eradication measures as quickly as possible, which may include taking systems offline, removing access, or applying patches.

Employees report incidents immediately to our security inbox. Impacted customers receive notification within 72 hours of confirmed impact. Post-incident reviews occur within one week.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Our incident management follows NIST SP 800-61 Rev. 2 framework with defined playbooks for common scenarios including data breaches, ransomware, and system compromises. Incidents are categorised by severity (P0-P3) with defined response procedures.

Users report incidents to a security inbox. Employees, customers, vendors, and bug bounty programmes serve as detection sources. The Security Incident Response Team triages all reports via private Slack channels.

We provide incident reports to impacted customers within 72 hours of confirmed impact. Post-incident debriefs occur within one week. External communications are issued solely by the CISO or authorised designee. Internal incident documentation remains confidential.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
W&B offers a 30-day free enterprise trial that lets users evaluate core features without committing to a paid plan. Included in the trial are most enterprise capabilities that help teams manage and track ML and GenAI workflows.
Link to free trial
Wandb.ai/site

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
LRQA Limited
ISO/IEC 27001 accreditation date
Thursday 27 November 2025
What the ISO/IEC 27001 doesn’t cover
The certificate scope covers the full company business operations, across all business locations, applicable and relevant to the delivery, deployment and management of IT solutions, support and services in accordance with Statement of Applicability Version 4, and is audit against the new 2022 standard.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
LRQA Limited
ISO 9001 accreditation date
Monday 17 February 2025
What the ISO 9001 doesn’t cover
The certificate scope covers the full company business operations, across all business locations, applicable and relevant to the Delivery, Deployment and Management of IT Solutions, Support and Services.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
Yes
Who accredited the PCI DSS certification
Barclaycard
PCI DSS accreditation date
Thursday 9 January 2025
What the PCI DSS doesn’t cover
Our PCI DSS certification applies exclusively to payment processing systems and hosted payment gateways and does not extend to non‑payment systems, corporate IT infrastructure, or business applications outside the cardholder data environment.
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
B5f066ef-ff99-48a9-94b0-23f1f0ee595b
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
2d75659c-9df3-4d75-9406-9052a6e68c4b
Other security certifications
Yes
Any other security certifications
IASME CYBER ASSURANCE LEVEL ONE

Social value

Section B - Commitment for Future: Delivery
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bidteam@xma.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.