Security
What we do not claim.
We hold no third party security certification yet, and this page names only what is in the product today.
Account security
The controls that ship today
- Two step verification at loginA second factor is asked for at sign in, and an administrator can require it for everyone in the workspace.
- Sessions that expireA session ends after a period of inactivity, and signing out everywhere ends this session at once and every other one within five minutes.
- A block on repeated failed sign insRepeated failed sign in attempts to one account from one network address are blocked for at least 15 minutes, so a list of passwords cannot be run against it from there.
- Password reset tokens, stored hashedA reset link is single use and time limited, and what the database holds is a hash of it, never the link itself.
- A security activity logSign ins, password changes, multi factor changes and session revocations are recorded and readable by the account holder.
- Access by role and by scopeA person sees the spaces, folders and lists they have been given. Administrators can narrow that further, and sharing is per entity rather than all or nothing.
- Export on every tierExport people, Spaces, Lists and tasks, Docs, SOPs, Tables, Goals and review cycles any time, on every tier including the free one. Files, canvases, forms, chat, Doc comments and review answers are not in the export yet, so ask us for a copy before you delete a workspace. Deleted Spaces, Folders, Lists, tasks, Docs, canvases, tables, forms, files and SOPs go to Trash first, where an Owner or Admin can bring them back; a deleted goal is gone at once.
Procurement
Send us your security questionnaire
Write to sales@workwrk.com and we answer what is true today, including where the answer is no.
Reporting a vulnerability: the same address, with enough detail to reproduce it. There is no bug bounty programme, so we will not promise a payment. We will confirm we received it and tell you what we did.