Security
Certifications
Worklio maintains ISO 27001, ISO 27018, and ISO 9001 certifications and SOC 2 Type II attestation, and supports HIPAA and PCI DSS compliance.
Cloud infrastructure
The platform was designed from scratch for the Microsoft Azure cloud and uses Azure’s built-in security features. Each instance is separated to protect each partner company, its customers, and its workers.
Access controls
A layered system of access rights restricts who can see client and employee information. IP restrictions, two-factor authentication, and a strong password policy are built into the platform and highly recommended for every client. Worklio personnel, including developers and support, have limited and controlled access.
Audit logging
Every change made on the platform, by administrators, employees, and clients alike, is recorded in an audit system, so all access and data changes can be reviewed.
Secure development
Code and task management run on Microsoft Azure DevOps. Builds and release deployments are handled only by Azure DevOps, so production binaries cannot be modified or injected with malicious code.
Encryption in transit
Data is transmitted using PCI-grade TLS encryption.
Testing and recovery
An outside firm completed penetration testing successfully. Source code and data are stored separately, which gives several options for fast recovery.
Responsible disclosure
If you believe you have found a security vulnerability, email [SECURITY EMAIL] with details and steps to reproduce. Please do not access or modify data that is not yours, and give us reasonable time to fix the issue before public disclosure.