Security

Security at WorkoAI

How we protect credentials, isolate tenant data, and keep agent actions auditable.

Our approach

WorkoAI is built for teams that trust AI agents with real workflows. Security is part of the product surface — credentials, tenant isolation, and auditability — not a bolt-on page. We design for least privilege, encryption by default, and clear customer control over connected tools.

Encryption and transport

API credentials and OAuth tokens are encrypted at rest (AES-256) and isolated per company. All traffic to the WorkoAI application uses TLS. Agents access connected systems only with the tokens and scopes you authorise.

Tenant isolation

Customer data is logically separated by company. Queries and agent execution are scoped to the authenticated workspace so one tenant cannot read another tenant's data, credentials, or audit history.

Access and audit

Human-in-the-loop approvals, role-based access inside your workspace, and immutable audit logs help you review what agents did and why. You can disconnect integrations at any time from settings; revoked provider tokens stop further API calls.

Compliance posture

We are building toward SOC 2-aligned controls and host on reliable cloud infrastructure. Enterprise customers who need a DPA, security questionnaire, or custom MSA can contact security@workoai.com or legal@workoai.com.

Related policies

Data processing for connected tools is described in our Privacy Policy. Acceptable use of integrations is covered in our Terms of Service. Cookie practices are summarised on our Cookies page.