Our approach
Compliance at WorkBOS is architectural, not aspirational: tenant isolation is enforced in the database, access is least-privilege by default, every agent action is audited, and data deletion is a real, scheduled, verifiable process. That foundation is what regulations ask for — the paperwork maps onto controls that already exist.
Privacy regulations
- GDPR / UK GDPR (EU & UK) — processor DPA available; SCCs + UK Addendum for transfers; data-subject rights supported in-product (access, export, correction, deletion); records of processing maintained.
- CCPA / CPRA (California) — no sale or sharing of personal information; access/deletion/portability honored; service-provider terms available.
- PIPEDA (Canada) — consent-based processing, openness and safeguards aligned with our privacy program.
- PDPL (Saudi Arabia) & UAE PDPL — regional data-protection alignment for GCC customers; processing purposes disclosed; cross-border transfer commitments on request.
- DPDP Act (India) — notice-and-consent alignment, purpose limitation, grievance contact.
- LGPD (Brazil) — legal bases and data-subject rights honored equivalently to GDPR.
Payments
All card processing is delegated to Stripe (PCI-DSS Level 1). WorkBOS never stores or transmits full card numbers, keeping our PCI scope to SAQ-A.
Certification roadmap
- SOC 2 Type I — control documentation in progress on our existing gates (RLS coverage, CI security scans, release audit trail, access reviews); target: audit engagement post-revenue.
- SOC 2 Type II — follows Type I after the observation window.
- ISO/IEC 27001 — ISMS scoped after SOC 2; many controls shared.
- HIPAA — not currently offered; WorkBOS is not intended for PHI. Healthcare operations without PHI are fine.
Data residency
Today the platform runs in our subprocessors’ cloud regions. Regional pinning (EU-only residency) and customer-managed model endpoints (BYO-LLM, available now) are on the roadmap for enterprise agreements.
Questionnaires & documentation
Security questionnaires, control matrices and architecture walkthroughs for enterprise or reseller due diligence: security@workbos.com.