Security & data privacy

Your data is yours. Your people’s time is theirs.

Monitoring only works when everyone trusts it. This page explains, in plain language, how Workkk protects your company’s data, what your employees can always count on, who helps us run the service, and how to report a security issue. Everything here describes the product as it works today.

Your data

How we protect your company’s data

Encrypted in transit

Every connection to Workkk - dashboard, API and desktop app - runs over HTTPS/TLS. Live screen sessions are peer-to-peer and DTLS-encrypted.

Hashed passwords

Passwords are hashed with bcrypt. We never store or see them in plain text, and the desktop app keeps its sign-in token in your OS keychain.

Workspace isolation

Every request is tied to one workspace and checked against the user’s membership. One email belongs to exactly one company.

Role-based access

Owner, admin, team lead and employee roles, plus per-employee permissions for HR documents and pay visibility.

No public links

Screenshots, chat files and HR documents are only served through signed-in, permission-checked requests - never a shareable URL.

Signed desktop updates

Every desktop update is cryptographically signed and verified before it installs. The macOS app is Developer ID-signed and notarized by Apple.

Audit trail

Remote sessions, member changes, HR-document actions, billing events and agreement acceptances are written to an audit log.

Delete on demand

Workspace owners can permanently delete their whole workspace - records, screenshots and files - in one step.

Your people

What your employees can always count on

A clear monitoring agreement

Employees read and accept a plain-language agreement in the desktop app. Acceptance is recorded with its version and time.

Breaks stay private

Scheduled screenshots run only while someone is checked in and working - never on a break or after check-out.

No keylogging

Keyboard and mouse activity is only counted to measure active time. What people type is never recorded.

Remote control needs a yes

Taking control of someone’s computer starts only after the employee approves the request.

Employees see their own data

People can review their own timeline, hours and screenshots - monitoring is never hidden from the person being monitored.

We never sell data

No advertising, no third-party analytics or tracking scripts, and personal data is never sold or rented.

Roles & law

Who is responsible for what

Your company is the data controller. You decide whether screenshots, app and website tracking or idle detection are switched on, and how often screenshots are taken. Workkk is your data processor: we process that data only to run the service for you, and we never use it for advertising.

Employee monitoring is regulated in many places - for example the EU and UK GDPR and India’s Digital Personal Data Protection Act. Tell your team what you monitor and why, keep only what you need, and check local employment law before you roll it out. Our Privacy Policy explains how we handle personal data. For privacy questions or data-subject requests, email [email protected].

Sub-processors

Who helps us run Workkk

The third parties that process data on our behalf. We update this list when it changes.

ProviderPurposeLocation
Workkk-operated serverApplication, database and file storageIndia
CloudflareDNS, TLS and network protectionGlobal edge
ResendTransactional email (invites, sign-in codes)United States
RazorpaySubscription paymentsIndia
GitHubHosting desktop app downloadsUnited States

Independent verification

We’re a young company, so we’d rather show you where we honestly are than flash badges we haven’t earned. Each one appears here with its proof once it’s issued.

  • On our roadmapCSA STAR Level 1Public security self-assessment (CAIQ)
  • On our roadmapIndependent penetration testBy a CERT-In empanelled auditor
  • On our roadmapISO/IEC 27001Certification by an accredited body
  • On our roadmapSOC 2 Type IIAttestation by an independent CPA firm
Responsible disclosure

Found a security issue? Tell us first.

Email a description and steps to reproduce. We’ll acknowledge your report, keep you updated while we fix it, and credit you if you’d like. Please give us a reasonable time to fix the issue before you share it publicly, and don’t access other people’s data, disrupt the service or use social engineering while you test.

[email protected]

Machine-readable contact: /.well-known/security.txt