Trust centre

Your data, your rules, and a record of every change.

Who can see what, who changed what, and when Workloom itself can look: each one enforced by the product and written down where your admins can read it.

Book a demoWorkloom for enterprise

The six controls

What the product enforces.

  • Roles and scopes Each permission reaches own, team, team and below, or everyone. Nobody grants more than they hold.
  • Activity log Before and after, who did it (a person, Wren, a rule or an integration) and who approved it. Kept for two years; nothing deletes it.
  • No standing access Workloom support sees your workspace only when an admin grants it: read-only, for at most 72 hours, and logged by name.
  • External access Agencies and operators get an end date, a sponsor on your team, and only the Weaves, lists and mailboxes you grant.
  • Data processing A Data Processing Addendum for customers, and the list of sub-processors below.
  • Your infrastructure Domains, inboxes and numbers are bought and held for your workspace, not shared with other customers.

Sign-in and sessions

Who gets in, and how you stop them.

  • Two-step verificationAn authenticator app with single-use recovery codes. Required for admins and anyone holding a high-risk permission, or for everyone if you choose.
  • Asked again before sensitive changesRoles, exports, deletes, API keys, webhooks and purchases ask for a fresh code, even in an open session.
  • Sessions end at onceSuspend someone, or remove them in an access review, and every session they have open ends, on the web and on their phone.
  • SSO user syncSCIMJoiners and leavers come from your identity provider over SCIM. Leavers are suspended, never deleted.
  • ConditionsLimit a role to your office networks or working hours; outside them it reads only, or is refused.

Wren and your records

Wren proposes. A person decides.

  • Staged, not savedWren stages record updates and email rewrites. Nothing is written until someone approves it, and the change runs with that person’s permissions.
  • Wren sees what the asker seesEvery question to Wren is answered inside the asker’s own reach. An admin can switch off whole areas Wren may read.
  • Credentials stay sealedConnection tokens are encrypted at rest, kept out of logs and never returned by the API.
  • Deletes can be undone for 30 daysCompany Brain material is deleted softly and purged after 30 days. Erasure requests remove a person from your workspace and keep them suppressed.

Sub-processors

Who processes data for us.

The companies Workloom relies on to run the service, and what each one does.

  • Microsoft AzureInfrastructureHosting, databases, storage and AI models (Azure OpenAI).
  • DeepgramVoiceSpeech to text for calls, voice notes and dictation.
  • GoogleChannelsGoogle Workspace mailboxes and calendars you connect.
  • CashfreeBillingPayments and invoices.
  • MixpanelAnalyticsProduct analytics inside the app.

Questions

For your security review

Can Workloom staff see our data?
Only when an admin in your workspace grants support access, for up to 72 hours (24 by default). Support gets a read-only seat that ends with the window, and everything it does is in your Activity log under “Workloom support”.
How long is the activity log kept?
Two years. There is no way to delete an event, for anyone. Admins can export it as CSV, and the export is itself logged.
Where is our data stored?
On Microsoft Azure, in the East US region. The Data Processing Addendum and the list of sub-processors are on the legal pages.

Bring your reviewer the mechanism.

Book a demo with your security lead, and we’ll walk through roles, the log and support access in your own workspace.