How your systems are hosted, protectedand watched.
What procurement asks before a contract: where data lives, who can reach it, how it is backed up, what happens when something breaks, and what we do with AI.
01Infrastructure
- Production, preview and development environments are isolated; preview URLs are not indexable
- Data region chosen per project (EU by default for European clients) and recorded in the proposal
- Encryption in transit (TLS 1.2+) and at rest on every managed database
02Access control
Least privilege
Each engineer gets only the access their task needs
MFA everywhere
Cloud consoles, repositories and databases
Named credentials
No shared logins; access removed on exit within 24 hours
Secrets manager
Vercel/AWS secrets; never in code, chat or tickets
Access reviewed quarterly
Every environment, every person
Your accounts, your admin
You hold owner rights; we are invited collaborators
03Secure development
- Every change is a pull request reviewed by a second engineer; AI-generated code is never merged unread
- Dependency scanning and automated tests in CI; performance and security headers enforced
- Server-side validation, parameterised queries, rate limiting and CSRF protection by default
- Webhooks verified by signature; payments idempotent; audit logs on money and permissions
04AI data rules
- Client and customer data is never used to train models
- Zero-retention API modes are used where the provider offers them; prompts and outputs are logged in your systems, not ours
- Agents act only through server-side guards; the model cannot write to your data directly
- Every model call is logged with cost; per-tenant caps stop runaway spend
05Backups and continuity
06Incidents and breaches
Alerts page a named engineer. Clients are told within 48 hours of a confirmed personal-data breach with cause, scope, action taken and next steps. Every incident ends with a written root-cause note that becomes a test or a control.
07Sub-processors
Vercel, Neon, Amazon Web Services, Google (Firebase/Cloud), Resend, Stripe, OpenAI, Anthropic, Groq. Full list, purposes and locations are in the Data Processing Agreement.
08Report a vulnerability
Email contact@workwox.com with “security” in the subject. We acknowledge within one business day and do not pursue researchers acting in good faith.
Questions about this document: contact@workwox.com. Workwox Private Limited — House 29C, Street 1, Hameedullah Mokal Colony, Sahiwal 57000, Pakistan · Fenix Väg 6-12, 134 44 Stockholm, Sweden.
Questions before
you sign?
An engineer, not a sales team, answers within one business day. NDA first if you prefer.
Write to us