Security & data handling

How your systems are hosted, protectedand watched.

What procurement asks before a contract: where data lives, who can reach it, how it is backed up, what happens when something breaks, and what we do with AI.

Last updated 18 September 2026Backups restored monthlySecrets in a managerClient data never trains models
HostingVercel, AWS, Firebase — region per project
AccessLeast privilege, MFA, per-person credentials
BackupsDaily, encrypted, restore-tested monthly
MonitoringLogs, tracing, alerts that reach a person

01Infrastructure

UsersTLS 1.2+ · HSTSEdge · WAFrate limits · headersApplicationVercel · isolated envDatabaseencrypted at rest · EUAI modelszero-retention APIsBackupsdaily · restore-testedMonitoringlogs · tracing · alertsSecretsmanager · rotated
  • Production, preview and development environments are isolated; preview URLs are not indexable
  • Data region chosen per project (EU by default for European clients) and recorded in the proposal
  • Encryption in transit (TLS 1.2+) and at rest on every managed database

02Access control

Least privilege

Each engineer gets only the access their task needs

MFA everywhere

Cloud consoles, repositories and databases

Named credentials

No shared logins; access removed on exit within 24 hours

Secrets manager

Vercel/AWS secrets; never in code, chat or tickets

Access reviewed quarterly

Every environment, every person

Your accounts, your admin

You hold owner rights; we are invited collaborators

03Secure development

  • Every change is a pull request reviewed by a second engineer; AI-generated code is never merged unread
  • Dependency scanning and automated tests in CI; performance and security headers enforced
  • Server-side validation, parameterised queries, rate limiting and CSRF protection by default
  • Webhooks verified by signature; payments idempotent; audit logs on money and permissions

04AI data rules

  • Client and customer data is never used to train models
  • Zero-retention API modes are used where the provider offers them; prompts and outputs are logged in your systems, not ours
  • Agents act only through server-side guards; the model cannot write to your data directly
  • Every model call is logged with cost; per-tenant caps stop runaway spend
Model providers used: OpenAI, Anthropic, Groq — chosen per project and switchable without a rewrite.

05Backups and continuity

Dailyencrypted backups
35 daysretention window
Monthlyrestore rehearsal, timed
Documentedrunbook per system

06Incidents and breaches

Alerts page a named engineer. Clients are told within 48 hours of a confirmed personal-data breach with cause, scope, action taken and next steps. Every incident ends with a written root-cause note that becomes a test or a control.

07Sub-processors

Vercel, Neon, Amazon Web Services, Google (Firebase/Cloud), Resend, Stripe, OpenAI, Anthropic, Groq. Full list, purposes and locations are in the Data Processing Agreement.

08Report a vulnerability

Email contact@workwox.com with “security” in the subject. We acknowledge within one business day and do not pursue researchers acting in good faith.

Questions about this document: contact@workwox.com. Workwox Private Limited — House 29C, Street 1, Hameedullah Mokal Colony, Sahiwal 57000, Pakistan · Fenix Väg 6-12, 134 44 Stockholm, Sweden.

Questions before
you sign?

An engineer, not a sales team, answers within one business day. NDA first if you prefer.

Write to us