Security & Trust
Built to earn the trust of teams that can’t afford to guess
Workser gives AI agents real access to your business — your data, your tools, your workflows. Here’s exactly how we protect that access, in plain terms, with no rounding up.
Encryption everywhere it matters
Secrets and connected-app credentials are encrypted at rest with per-record random IVs and versioned keys that support rotation without downtime. All traffic runs over TLS in transit.
Scoped access, least privilege
AI agents authenticate with scoped API keys, not your personal session. Destructive actions like deleting a project require an authenticated dashboard user or a management-scoped key — never a runner key alone.
Isolated, disposable AI execution
When an AI agent writes or runs code, it happens inside an ephemeral sandbox created for that task and destroyed when the task ends — never reused across customers or tasks.
Built for prompt-injection resistance
Agents are instructed to treat uploaded files and tool output as untrusted data, not instructions, and any secret-shaped value in tool output is automatically masked before the model can see it.
Human approval where it counts
Computer-use actions require your explicit per-action approval before they execute. AI agents can pause and request human sign-off before proceeding on a sensitive step.
Dedicated infrastructure for paid teams
Every project on a paid Workser plan gets its own dedicated database and file storage — not a shared schema with other customers.
Your data stays yours
You own everything you put into Workser — your content, your files, your workflow configurations — and everything your AI agents generate on your behalf. We do not use your prompts, files, or AI outputs to train our models or improve anyone else’s experience, unless you give us prior written consent. When a request has to be routed to a third-party AI model provider, we send only what’s necessary to handle that request, under that provider’s own data-handling terms.
Isolation between customers
Every project on a paid Workser plan runs on its own dedicated database and file storage — not a shared schema with other customers’ data. Free-tier projects currently share infrastructure as a cost trade-off; if dedicated isolation is a requirement for your organization, our paid tiers already provide it, and we’re happy to confirm the specifics for your security review.
Compliance program
We’d rather tell you honestly where we are than round up. Here’s our current status:
| Item | Status | Notes |
|---|---|---|
| SOC 2 Type II | In progress | Audit engagement underway. |
| ISO/IEC 27001 | In progress | Certification work underway. |
| ISO/IEC 27701 | Roadmap | Planned following ISO 27001. |
| ISO/IEC 42001 | Roadmap | AI management system standard — planned. |
| Data Processing Agreement | Available on request | Contact us to review for your organization. |
Need our full security whitepaper, subprocessor list, or a signed DPA for a vendor risk review? Email support@workser.ai and we’ll get you what you need.