Security
What we do not claim.
We hold no third party security certification yet, and this page names only what is in the product today.
Account security
The controls that ship today
- Two step verification at loginA second factor is asked for at sign in, and an administrator can require it for everyone in the workspace.
- Sessions that expireA session ends after a period of inactivity, and signing out everywhere ends every session on every device at once.
- Lockout after repeated failuresRepeated failed sign in attempts lock the account rather than letting a list of passwords be tried against it.
- Password reset tokens, stored hashedA reset link is single use and time limited, and what the database holds is a hash of it, never the link itself.
- A security activity logSign ins, password changes, multi factor changes and session revocations are recorded and readable by the account holder.
- Access by role and by scopeA person sees the spaces, folders and lists they have been given. Administrators can narrow that further, and sharing is per entity rather than all or nothing.
- Your data leaves with youExport is available on every tier including the free one, any time. Deleted items sit in a trash window before they go.
Procurement
Send us your security questionnaire
Write to sales@workwrk.com and we answer what is true today, including where the answer is no.
Reporting a vulnerability: the same address, with enough detail to reproduce it. There is no bug bounty programme, so we will not promise a payment. We will confirm we received it and tell you what we did.