WWorkIn← Back to home

Security Overview

Last updated: 21 June 2026

This document may be updated from time to time.

Security and data protection are core to how WorkIn is built. This overview describes the measures we use to protect customer data. It reflects our current practices and is not a certification; we describe only safeguards we actually apply.

1. Data protection

Data is encrypted in transit using TLS, and data stored on our infrastructure is encrypted at rest. Passwords are never stored in plain text — they are held only in salted, hashed form by our authentication provider.

2. Tenant isolation

WorkIn is multi-tenant, and each customer’s data is logically separated. Access is enforced at the database level using row-level security policies scoped to a customer’s organization, so one customer cannot access another customer’s data.

3. Access controls

  • Role-based access control — within an organization, what each person can see and do is governed by their role (for example, owner, admin, HR, manager, employee).
  • Two-factor authentication — accounts can enable 2FA for an additional layer of sign-in protection.
  • Least privilege — internal access to systems is limited to what is needed to operate and support the Service.

4. Infrastructure

We run WorkIn on reputable cloud infrastructure providers that maintain physical and network security for their facilities. Where data is processed outside the Kingdom of Saudi Arabia, we apply safeguards consistent with the PDPL, as described in our Privacy Policy.

5. Reliability and availability

We monitor the Service and maintain backups to support recovery. We aim for high availability, but the Service is provided without a guarantee of uninterrupted access; planned maintenance and factors outside our reasonable control may affect availability. Specific availability commitments, where offered, are set out in the applicable agreement.

6. Your role in security

  • Keep your credentials confidential and enable two-factor authentication.
  • Grant roles on a least-privilege basis and remove access promptly when someone leaves.
  • Only upload data you are authorized to process.

7. Responsible disclosure

If you believe you have found a security vulnerability, please report it to security@getworkin.net. We appreciate responsible disclosure and will work to address valid reports promptly. Please do not publicly disclose an issue before we have had a reasonable opportunity to respond.

8. Contact

For security questions, contact security@getworkin.net.