Trust
How WorkBOS protects your workspace from attacks
WorkBOS watches the whole platform for attacks around the clock and stops the obvious ones on its own. You do not need to set anything up.
- Sign-in protection: every wrong password makes the next attempt slower to try, the account owner gets an email after repeated failures, and one address trying passwords on several accounts is blocked automatically.
- Robots and scanners: requests for the secret files that badly set-up websites leak (for example .env or .git) are recorded, and the address asking is blocked. We never had those files, so nothing is exposed.
- Speed limits: sign-in, sign-up, password reset, public forms, bookings and our API all have limits, so a flood of requests is turned away instead of slowing everybody else down.
- Risky changes: our team is alerted when admin rights change, when two-step sign-in is removed from an admin, and when a workspace exports or deletes an unusually large amount of data in a short time.
- Tested every day: WorkBOS tries to break into itself from the outside every six hours and runs a full security test every day, including a practice attack each week, and again whenever a real attack is noticed. If a defence stops working, our team is told straight away.
The strongest protection for your own account is two-step sign-in. Turn it on in Settings ▸ Security, and ask the owners and admins of your workspace to do the same.
Was this page useful?