Security and compliance you can trust

Worktrace protects your data with enterprise-grade security and compliance built into every layer of the platform.

Privacy Compliance & Data Governance

Worktrace maintains documented security and privacy controls for handling sensitive customer data, including GDPR, HIPAA and SOC 2 Type II-aligned practices. Personal data is processed only on a valid legal basis and protected through defined privacy controls, retention rules, and secure disposal procedures.

Data Protection (Encryption + Redaction)

Worktrace protects sensitive customer data through encryption and privacy-preserving controls. Data at rest is encrypted using AES-256, and data in transit is protected using TLS 1.2+. Worktrace also supports automatic detection and redaction of sensitive data, including PII, PHI, and PCI, to reduce privacy risk and prevent accidental exposure in workflows.

Identity & Access Control

Worktrace applies strict access controls to ensure customer data is accessible only on a need-to-know basis. Privileged access requires MFA, access is logged and reviewed, and access rights are removed promptly upon role change or termination per defined timelines.

Application & Integration Governance (Allowlisting / Blocklisting)

Worktrace enables customers to control which tools and applications can be used within workflows. This includes blacklist/whitelist (blocklist/allowlist) controls, helping organizations restrict unapproved applications and reduce operational and data leakage risk.

AI Agent Controls, Consent & Auditability

Worktrace provides granular controls to manage AI agent behavior and user-level permissions: User consent controls to require explicit approval for sensitive actions, Agent permissioning to define what actions agents may perform, and Audit trails to maintain visibility into agent activity and decision-making. This ensures accountability, reduces unintended actions, and supports enterprise governance requirements.

Single Sign-On (SSO) & Authentication

Worktrace supports enterprise-grade authentication controls including Single Sign-On (SSO), enabling customers to centrally manage user access through their identity provider. This strengthens access governance, simplifies onboarding/offboarding, and reduces risks from password-based authentication through standardized sign-in policies and access control enforcement.

Infrastructure Security & Cloud Hardening

Worktrace runs on secure cloud infrastructure governed through defined operational security controls including least-privilege IAM, hardened configuration baselines (e.g., CIS/NIST principles), restricted network rules, controlled administrative access, patch SLAs, and network segmentation. Production network settings are change-controlled and managed only by authorized personnel.

Monitoring, Logging & Incident Response

Worktrace maintains security logging, auditing, and incident response processes designed to detect, investigate, and respond to suspected security events. Logging is retained based on policy-defined schedules, and security incidents must be reported immediately through defined escalation mechanisms. HIPAA breach handling procedures include risk assessment, investigation, and notification timelines in accordance with applicable requirements.

Data Retention, Deletion & Secure Disposal

Worktrace follows formal data management practices to ensure information is classified, retained only as required, and securely disposed of. Devices are securely wiped or destroyed depending on condition and risk, and certificates of destruction are retained where applicable.

Let's Talk Further

Start a free trial or email us. We'll spin up a live workflow for you, free of charge, in under a week.