Skip to content

Security and Compliance

Security questions deserve direct answers. This page summarizes how WorkDone hosts, protects, and isolates your data across Corporate Memory and AI Transformation Accelerator engagements, and how to get the deeper documentation your security team may need.

For more, visit the WorkDone Trust Center at workdone.ai or email support@workdone.ai.


Hosting

WorkDone products run on Microsoft Azure, inheriting the physical, network, and operational security of Microsoft's cloud platform. WorkDone does not operate its own data centers.

Encryption

  • In transit: all traffic between your users and WorkDone products, and between WorkDone and your integrated systems, is encrypted using TLS. The portals are served exclusively over HTTPS.
  • At rest: customer data is encrypted at rest within the Azure-hosted environment.

Tenant isolation

Tenancy is organization-scoped throughout the platform. Every record carries your organization's identity, and core resources, including each organization's knowledge store, are provisioned per organization. Your documents, ERP working data, analytics, reports, and users are not visible to any other customer, and cross-tenant requests are rejected at the API layer.

Access control

  • Least-privilege RBAC. Corporate Memory enforces four roles (Admin, Management, Automation, Member) on every page and API request, not just in the navigation. See Security and Access for how to assign them well.
  • Invitation-only provisioning. There is no public sign-up for any WorkDone product. Accounts exist only because an administrator in your organization (or WorkDone, as part of your engagement) created them.
  • Passwordless authentication. Where WorkDone products use direct sign-in, it is passwordless: single-use, short-lived one-time passcodes delivered by email. There are no passwords to phish, reuse, or breach.
  • Least-privilege integrations. Connections to your systems (SharePoint, Google Drive, Teramind, and your business systems) use dedicated, narrowly scoped accounts, read-only wherever possible, and are revocable by you at any time.

AI and your data

Your data is used only to serve your organization: answering your users' questions, generating your reports, powering your dashboards. It is not used to train AI models. Copilot answers are grounded in your own documents and carry citations so users can verify them, and a human approval queue in your organization gates what enters the knowledge base.

Assessment anonymization

AI Transformation Assessment reports anonymize participants by default: findings are presented at the team and pattern level rather than as named-individual profiles, and telemetry collection is scoped to an observation window agreed with you in advance. Guidance for running assessments responsibly on your side is in Data Governance.

SOC 2 program

WorkDone maintains a SOC 2 compliance program covering its products and operations. SOC 2 reports, security questionnaire responses, and related compliance documentation are available to customers and qualified prospects under NDA; email support@workdone.ai to request them.

For data-processing terms, data residency details, or other regulatory questions, contact support and we'll respond against your agreement.

Vulnerability management

Security is an ongoing practice, not a point-in-time exercise:

  • Dependency and container image scanning runs as part of WorkDone's build and release process, so known vulnerabilities are identified before software ships and tracked to remediation.
  • Regular patching of platform components and dependencies.
  • Security review is part of the engineering lifecycle for new features and integrations.

Responsible disclosure

If you believe you've found a security vulnerability in a WorkDone product, email support@workdone.ai with "Security" in the subject line. Include what you found, where, and how to reproduce it, and please don't access data that isn't yours or test in ways that could disrupt service. Security reports are prioritized ahead of the normal support queue, and we'll acknowledge your report and keep you informed through resolution.


Requesting security documentation

You need Do this
SOC 2 report or security questionnaire Email support@workdone.ai; provided under NDA
Data-processing terms, residency, retention Email support@workdone.ai; answered against your agreement
Integration security details See the integration guides, then support for anything deeper
To report a vulnerability Email support@workdone.ai with "Security" in the subject
The broader Trust Center Visit workdone.ai