Enterprise security you can actually verify
Worksome is built for procurement teams that care about data.
We meet the standards your legal, IT, and security teams require. And we can prove it.
Security built into every layer
From infrastructure to access controls, Worksome is designed so that enterprises can deploy confidently without making exceptions to their security policy.
Hosted on AWS with an edge security layer provided by Cloudflare (DNS, WAF, and DDoS protection).
Role-based access control (RBAC), SSO/SAML 2.0 support, and mandatory MFA for all internal staff. Principle of least privilege applied across all systems.
All data encrypted at rest (AES-256) and in transit (TLS 1.2+). Encryption keys managed via AWS KMS with annual rotation. No plaintext data leaves our boundary.
24/7 automated anomaly detection, centralized audit logging retained for 12 months, and a Security Information and Event Management (SIEM) system in place.
All sub-processors reviewed against our security standards before onboarding. Full sub-processor list available here. Annual reassessment mandatory.
Automated daily backups with cross-availability-zone replication (Multi-AZ). DR tested annually with documented runbooks.
Worksome Intelligence
Worksome's AI features are built to support human decision-making, not replace it. Where AI output informs a material decision, a qualified Worksome staff member validates it before it is finalized.
In accordance with Article 50 of the EU AI Act, users are explicitly notified when interacting with an AI system.
Worksome Intelligence focuses strictly on administrative efficiency and document retrieval.
Independent verification, not just our word
Third-party audits and internationally recognized frameworks are how we prove our security posture, not how we describe it.
SOC 2 Type II
Annual audit by: Audit Peak
Independent SOC 2 Type II examination covering Security, Availability, and Confidentiality for the period January 1 to March 31, 2026.
Covers three Trust Services Categories: Security, Availability, and Confidentiality
Full report available to enterprise customers and prospects under NDA
Continuous control monitoring between audits via automated tooling
GDPR & Data Protection
Our data-protection program is designed to support GDPR, UK GDPR, and applicable US privacy-law requirements. A Data Processing Addendum is available for customers.
Data Processing Agreement (DPA) available for all customers
Data Protection Officer appointed; contact: dpo@worksome.com
Privacy by design embedded in product development lifecycle
International transfers are governed by appropriate safeguards, including EU Standard Contractual Clauses and, where applicable, the UK IDTA or UK Addendum, unless an adequacy decision or another permitted transfer mechanism applies.
Retention schedules documented and enforced via automated deletion
Data subject and consumer rights requests (access, deletion, portability) documented and tested
Your data stays in the EU
All Worksome data is stored and processed in the European Union, hosted on AWS with GDPR compliance built in, not bolted on. For UK and US clients, that means clear, verifiable answers to residency questions in procurement and DPAs.
EU-hosted infrastructure
All production data in AWS eu-west-1 (Ireland) & eu-central-1 (Frankfurt)
GDPR by default
All data handled under EU jurisdiction and GDPR
One answer for global procurement
UK and US clients are served from EU infrastructure · full transparency in our DPA
Clarity on who owns what
Enterprise procurement teams often ask how responsibilities are split.
Here's exactly how it works between Worksome and your organization.
Fast, transparent response, every time
Enterprise procurement teams need to know exactly what happens during a security event.
Here is our committed response timeline.
Triage
Containment
Notification
Regulatory
See how Worksome secures your global workforce
Join a 1:1 walkthrough of our platform and security architecture.
We’ll show you our AI guardrails and data residency controls.
Frequently Asked Questions about Security
Worksome undergoes an independent SOC 2 Type II examination covering the Security, Availability, and Confidentiality Trust Services Criteria. The report covers the period January 1 to March 31, 2026.
All Worksome production data is stored and processed in the European Union, on AWS infrastructure in eu-west-1 (Ireland) and eu-central-1 (Frankfurt).
No, all clients are hosted on our EU infrastructure. If your organization has specific residency requirements, contact us and we'll walk through the details together.
All data is encrypted at rest using AES-256 encryption with keys managed via AWS KMS. Data in transit is protected using TLS 1.2 or higher. We enforce encryption across all production environments to ensure no plaintext data leaves our secure boundary.
We maintain a documented Incident Response Plan. In the event of a confirmed personal data breach, Worksome notifies the relevant customer without undue delay in accordance with the Data Processing Addendum. As a processor, Worksome supports its customers in meeting their own regulatory notification obligations, including the 72-hour window under GDPR Article 33.
Yes. Worksome supports SAML 2.0 for enterprise-grade identity management. This allows your organization to enforce your own Multi-Factor Authentication (MFA) and password policies through providers like Okta, Microsoft Entra ID, or Google Workspace.
All third-party sub-processors undergo a rigorous security and privacy impact assessment before onboarding. We maintain a transparent Sub-processor List and enter into Data Processing Agreements (DPAs) with all vendors to ensure they meet our strict security standards.
We perform continuous automated vulnerability scanning and conduct penetration testing at least annually, performed by an independent third-party security firm. Any identified vulnerabilities are triaged and remediated according to our internal security patching policy.
We employ a Human-in-the-Loop workflow where AI-generated outputs are manually reviewed by qualified staff before finalization to prevent autonomous decision-making errors.
Worksome Intelligence is designed to meet the transparency requirements of Article 50 of the EU AI Act. Users are notified when they are interacting with an AI system, and AI-generated outputs are reviewed by qualified Worksome staff before they are finalized.
Didn't find your answer? Ask Worksome
Sourcing, compliance, payments, classification.
Get straight answers about your external workforce, instantly.
