Security

Customer data, protected
by clear boundaries.

WRKZY protects customer operations with scoped access, account security, encrypted provider credentials, audit evidence, and governed AI and automations.

Security controls in the current service

These are controls present in WRKZY today. They describe the product as it operates now, not future functionality or an independent certification.

Workspace and data boundaries

Application authorization and database-level row access policies restrict access to the active workspace. Membership is checked before protected data is accessed, and restricted team inboxes create a narrower visibility boundary where configured.

Roles and least privilege

Owner, Admin, and Member roles separate responsibilities. Access can be invited, reviewed, reduced, disabled, or revoked as teams and responsibilities change.

Account and session security

Users can protect their account with authenticator MFA, review active sessions, and end individual, other, or all sessions. Personal passwords, MFA secrets, and session tokens are not exposed through workspace administration.

Protected provider connections

Provider access tokens, OAuth credentials, and SMTP passwords are encrypted before storage using AES-256-GCM and handled by server-side systems. Sensitive connection flows use signed state.

Verified events and audit evidence

Where providers supply signed webhooks, WRKZY verifies signatures before accepting events. Owners can review authentication events and sessions, while administrative change history records consequential configuration activity when available.

Governed AI and automations

Workspace AI is limited by capability and context controls, with human review required before customer-facing use. Configured automations support testing, approval, version history, execution logs, retries, pause, and rollback.

Private and shared work remain distinct.

Team inbox membership can restrict customer work to the people responsible for it. Private Mail is owner-scoped and remains outside team search, shared timelines, and team AI unless its owner deliberately shares an approved scope or moves future replies into team-managed Work.

Linking a private thread to a CRM record does not by itself expose its subject, participants, messages, or attachments. Eligible approved shares can be revoked while their audit record remains available.

You decide which provider accounts connect.

Your organization connects its own supported communication provider accounts to WRKZY. Current availability includes WhatsApp and Email. You remain responsible for provider users, permissions, message content, recipients, and provider-policy compliance.

WRKZY processes connected-channel data to provide, secure, monitor, troubleshoot, and support the requested service, including conversations, templates, delivery events, customer context, and configured workflows. Disconnecting a provider stops future access or synchronization after the connection is disabled, subject to queued operations and documented retention.

AI assistance stays bounded and reviewable.

When available and enabled, WRKZY can use authorized workspace context to prepare summaries, drafts, rewrites, recommendations, and CRM suggestions. Owners and Admins control supported capabilities and context access. Record permissions continue to apply.

Human review is required, AI auto-send and automatic CRM updates are disabled, and people decide whether and how to use the output. WRKZY records operational usage metadata for audit and troubleshooting but does not persist raw provider prompts or responses in its application database.

Your part in keeping WRKZY secure.

Product controls work best when workspace access, connected accounts, and customer permissions are kept current.

  • Invite only authorized workspace users and review access regularly.
  • Protect login credentials and connected provider accounts.
  • Maintain lawful recipient permissions, templates, audiences, and customer data.
  • Review AI-assisted output and configured automations before relying on them.
  • Report suspected misuse or unauthorized access promptly.

Clear about what is verified.

This page describes controls implemented in the current WRKZY service. WRKZY does not currently claim SOC 2, ISO 27001, HIPAA, or another independent security certification.

Security practices will be updated as the service, infrastructure, and independent assurance program mature.

Found a security concern?

Share the affected workspace, approximate time, what you observed, and safe reproduction steps where available.

Do not submit passwords, verification codes, provider tokens, private keys, payment information, or unnecessary customer data.

Submit a security report