Back to home

Compliance

Where WorkBOS stands today: the regulations we align with, where data is stored, and the certifications we do not hold. Last updated July 28, 2026.

Our approach

Our controls are enforced in the platform rather than described in a policy: tenant isolation is enforced by the database, access is least-privilege by default, every agent action is audited, and deletion is a scheduled, verifiable process. This page states what that does and does not amount to in regulatory terms, including where it falls short.

Data residency

  • Your records: Database, file storage and backups (Postgres on AWS), hosted by Supabase in ap-southeast-1 (Singapore).
  • Web tier: Web application, serverless functions and edge routing; static assets from Vercel’s global CDN, hosted by Vercel in iad1 (US East, Northern Virginia).
  • Regional pinning (for example EU-only residency) is not available today. Customer-managed model endpoints (BYO-LLM) are available now and keep AI processing under your own provider agreement.

The full vendor list, with the data each one touches, is on /subprocessors.

International transfers

Workspace data is stored in Singapore (ap-southeast-1), which is outside the EEA and the UK. Transfers out of the EEA and the UK therefore happen for every EU and UK customer, and the mechanism is the Standard Contractual Clauses (with the UK Addendum) in our Data Processing Addendum, backed by the same clauses with each subprocessor.

The clauses themselves, and how to execute them, are in our Data Processing Addendum.

Privacy regulations

  • GDPR / UK GDPR (EU & UK), processor DPA available; SCCs + UK Addendum for transfers; data-subject rights supported in-product (access, export, correction, deletion); records of processing maintained.
  • CCPA / CPRA (California), no sale or sharing of personal information; access/deletion/portability honored; service-provider terms available.
  • PIPEDA (Canada): consent-based processing, openness and safeguards aligned with our privacy program.
  • PDPL (Saudi Arabia) & UAE PDPL, regional data-protection alignment for GCC customers; processing purposes disclosed; cross-border transfer commitments on request.
  • DPDP Act (India): notice-and-consent alignment, purpose limitation, grievance contact.
  • LGPD (Brazil): legal bases and data-subject rights honored equivalently to GDPR.

Certification status

WorkBOS holds no third-party security or compliance certifications today. We have no SOC 2 Type I or Type II report, no ISO/IEC 27001 certificate, no HIPAA attestation and no PCI DSS attestation of our own.

  • SOC 2 Type I: not held. No audit engagement has begun. We document controls internally (row-level-security coverage, CI security gates, release audit trail, access reviews) so an audit is possible later.
  • SOC 2 Type II: not held. A Type II requires an observation window after a Type I, so it cannot precede one.
  • ISO/IEC 27001: not held. No ISMS has been certified and no certification body is engaged.
  • HIPAA: not held. No HIPAA attestation and no Business Associate Agreement. WorkBOS is not intended for protected health information.
  • PCI DSS: not held. We hold no PCI DSS attestation of our own. Card data is handled by Stripe (PCI DSS Level 1) and is never stored or transmitted by WorkBOS, which keeps our scope to SAQ-A.

We will publish a report here when one exists, with the auditor named and the observation period stated. Until then, treat any WorkBOS certification claim you see anywhere as false.

Payments

All card processing is delegated to Stripe (PCI DSS Level 1). WorkBOS never stores or transmits full card numbers, keeping our PCI scope to SAQ-A.

The questions buyers actually ask

Every answer below is the answer we give in a security questionnaire. Nothing here is marked up for search engines that is not written on this page.

Where is WorkBOS data stored?
Workspace records (database rows, uploaded files and backups) are stored by Supabase in ap-southeast-1 (Singapore). The web tier runs on Vercel with iad1 (US East, Northern Virginia) as its primary serverless and edge region, and static assets are served from Vercel’s global CDN. We do not offer regional pinning today.
Which privacy regulations does WorkBOS align with?
GDPR and UK GDPR (as processor for workspace content, controller for account and billing data), CCPA/CPRA, PIPEDA, the Saudi and UAE PDPL, India’s DPDP Act and Brazil’s LGPD. Alignment means our processing terms, data-subject rights handling, retention and security measures are built to those requirements; it does not mean a regulator or auditor has certified us.
What is the legal basis and mechanism for international data transfers?
Workspace data is stored in Singapore (ap-southeast-1), which is outside the EEA and the UK. Transfers out of the EEA and the UK therefore happen for every EU and UK customer, and the mechanism is the Standard Contractual Clauses (with the UK Addendum) in our Data Processing Addendum, backed by the same clauses with each subprocessor. For EU and UK customers the lawful bases for our own processing are contract, legitimate interests, consent and legal obligation, as set out in our Privacy Policy at /privacy.
How do I exercise data-subject or CCPA/CPRA rights, and how quickly do you respond?
Email privacy@workbos.com, or use /contact. Access, export and correction are also self-serve in the product, and workspace deletion is self-serve. We verify identity before acting, and authorised agents must show proof of authorisation. We acknowledge within 5 business days and respond substantively within 30 days of verifying identity, extendable where the law you are relying on allows it for complex requests (a further 60 days under CPRA, a further two months under GDPR Art. 12(3)). We tell you inside the first 30 days if we need that extension. If you are an end user of a workspace someone else operates, we direct the request to that workspace’s administrator, who controls the data. We do not sell or share personal information, and we do not discriminate against you for exercising a right.
How long do you keep data, and what happens when I delete it?
Workspace content is kept for the life of the workspace plus the deletion retention window, then purged. Deletion is scheduled with a cancellation window before it becomes permanent; trash and soft-deleted records stay restorable by admins until purged. Account data is kept for the life of the account plus up to 90 days. Billing records are kept for 7 years or as long as tax law requires. Security logs are kept for 12 months. Backups roll off on a fixed schedule, so deleted data ages out of them rather than being removed individually. These are the periods in our Privacy Policy at /privacy.
How will I be told if you add or change a subprocessor?
Our subprocessor list is published at /subprocessors with the date it was last reviewed (currently 2026-07-28) and currently names 6 vendors. Material changes are announced in-product. If you have executed our Data Processing Addendum at /dpa, we notify you before a new subprocessor starts processing your data and you have the right to object.
What happens if there is a data breach?
Under our Data Processing Addendum at /dpa we notify you without undue delay after becoming aware of a personal-data breach affecting your workspace, with the information you need for your own regulatory notifications. Vulnerability reports go to security@workbos.com.
Are you SOC 2 or ISO 27001 certified?
No. WorkBOS holds no third-party security or compliance certifications today. We have no SOC 2 Type I or Type II report, no ISO/IEC 27001 certificate, no HIPAA attestation and no PCI DSS attestation of our own. We will not imply otherwise, and we will not send you an audit report that does not exist. What we do have is documented and testable: database-enforced row-level security for tenant isolation, role-based access control with per-page permissions, virus-scanned uploads that fail closed, encrypted secrets, signature-verified payment webhooks and security gates on every pull request. The control detail is at /security.
Who stores card data?
Stripe, which is PCI DSS Level 1. WorkBOS never stores or transmits full card numbers, which keeps our own scope to SAQ-A. We hold no PCI DSS attestation of our own.
Can you sign our DPA, and who is the contracting party?
Yes. Shahzad & Rainer LLC, doing business as WorkBOS, is the contracting party and the processor for workspace content. Email legal@workbos.com from your workspace owner account with your legal entity name and registered address; we countersign and return a copy. Our own Addendum, including the Standard Contractual Clauses and UK Addendum, is at /dpa.

Questionnaires & documentation

Security questionnaires, control matrices and architecture walkthroughs for enterprise or reseller due diligence: security@workbos.com.