Trust Center / Security

Security at Workiflow.

We protect your data like it's our own. When you trust us with your technology, that responsibility is non-negotiable. Here's how we back that up.

01 / Certifications
SOC 2 Type II — certified

SOC 2 Type II

Certified · Apr–Jul 2026 · report under NDA

The AICPA attestation for independently audited controls. Our SOC 2 Type II examination covers the Security trust services criterion for the period April 20 to July 20, 2026, and received an unqualified opinion from Prescient Assurance.

ISO 27001 — program in progress

ISO 27001

Coming soon · audit in progress

The international standard for information security management systems (ISMS). Our ISO 27001 program is in progress.

02 / How We Protect Your Data

Our security posture.

/01Access ControlsRole-based access with least-privilege enforcement. Team members only access the systems and data they need for their specific role, nothing more.
/02EncryptionData is encrypted in transit (TLS 1.2+) and at rest. We enforce encryption standards across every system and integration we manage.
/03Continuous MonitoringActive vulnerability monitoring and threat detection powered by At-Bay Stance, our embedded security platform, keeping our environment under constant watch.
/04Incident ResponseA documented incident response plan with defined roles, escalation paths, and communication protocols. If something happens, we move fast and transparently.
/05Vendor & Platform SecurityWe vet every platform and tool in our stack against security, compliance, and data handling standards before it touches client data.
/06Employee Security TrainingRegular security awareness training and phishing simulations for all team members. Human error is the biggest attack vector. We take it seriously.
03 / Insurance & Liability

Backed by comprehensive coverage.

/01Errors & Omissions InsuranceComprehensive professional liability coverage protecting against claims arising from errors, omissions, or negligence in the technology services we deliver.
/02Comprehensive Cyber LiabilityCoverage including data breach response, network security liability, regulatory defense, business interruption, ransomware events, and incident recovery costs.

04 / Transparency

SOC 2 report: available now.

Our SOC 2 Type II examination covered the period April 20 to July 20, 2026 and received an unqualified opinion from Prescient Assurance. We share the full report with prospective and current clients under NDA — if you're evaluating Workiflow or running a vendor security review, get in touch and we'll send it across. Our ISO 27001 audit is still in progress.

/ Start

Start with one request.

Book a discovery call. We'll assess your stack, find the quick wins, and show you what a managed partner actually looks like.

30 minutes. No commitment.