Your data is yours. Your people’s time is theirs.
Monitoring only works when everyone trusts it. This page explains, in plain language, how Workkk protects your company’s data, what your employees can always count on, who helps us run the service, and how to report a security issue. Everything here describes the product as it works today.
How we protect your company’s data
Encrypted in transit
Every connection to Workkk - dashboard, API and desktop app - runs over HTTPS/TLS. Live screen sessions are peer-to-peer and DTLS-encrypted.
Hashed passwords
Passwords are hashed with bcrypt. We never store or see them in plain text, and the desktop app keeps its sign-in token in your OS keychain.
Workspace isolation
Every request is tied to one workspace and checked against the user’s membership. One email belongs to exactly one company.
Role-based access
Owner, admin, team lead and employee roles, plus per-employee permissions for HR documents and pay visibility.
No public links
Screenshots, chat files and HR documents are only served through signed-in, permission-checked requests - never a shareable URL.
Signed desktop updates
Every desktop update is cryptographically signed and verified before it installs. The macOS app is Developer ID-signed and notarized by Apple.
Audit trail
Remote sessions, member changes, HR-document actions, billing events and agreement acceptances are written to an audit log.
Delete on demand
Workspace owners can permanently delete their whole workspace - records, screenshots and files - in one step.
What your employees can always count on
A clear monitoring agreement
Employees read and accept a plain-language agreement in the desktop app. Acceptance is recorded with its version and time.
Breaks stay private
Scheduled screenshots run only while someone is checked in and working - never on a break or after check-out.
No keylogging
Keyboard and mouse activity is only counted to measure active time. What people type is never recorded.
Remote control needs a yes
Taking control of someone’s computer starts only after the employee approves the request.
Employees see their own data
People can review their own timeline, hours and screenshots - monitoring is never hidden from the person being monitored.
We never sell data
No advertising, no third-party analytics or tracking scripts, and personal data is never sold or rented.
Who is responsible for what
Your company is the data controller. You decide whether screenshots, app and website tracking or idle detection are switched on, and how often screenshots are taken. Workkk is your data processor: we process that data only to run the service for you, and we never use it for advertising.
Employee monitoring is regulated in many places - for example the EU and UK GDPR and India’s Digital Personal Data Protection Act. Tell your team what you monitor and why, keep only what you need, and check local employment law before you roll it out. Our Privacy Policy explains how we handle personal data. For privacy questions or data-subject requests, email [email protected].
Who helps us run Workkk
The third parties that process data on our behalf. We update this list when it changes.
| Provider | Purpose | Location |
|---|---|---|
| Workkk-operated server | Application, database and file storage | India |
| Cloudflare | DNS, TLS and network protection | Global edge |
| Resend | Transactional email (invites, sign-in codes) | United States |
| Razorpay | Subscription payments | India |
| GitHub | Hosting desktop app downloads | United States |
Independent verification
We’re a young company, so we’d rather show you where we honestly are than flash badges we haven’t earned. Each one appears here with its proof once it’s issued.
- On our roadmapCSA STAR Level 1Public security self-assessment (CAIQ)
- On our roadmapIndependent penetration testBy a CERT-In empanelled auditor
- On our roadmapISO/IEC 27001Certification by an accredited body
- On our roadmapSOC 2 Type IIAttestation by an independent CPA firm
Found a security issue? Tell us first.
Email a description and steps to reproduce. We’ll acknowledge your report, keep you updated while we fix it, and credit you if you’d like. Please give us a reasonable time to fix the issue before you share it publicly, and don’t access other people’s data, disrupt the service or use social engineering while you test.
[email protected]Machine-readable contact: /.well-known/security.txt