Third Party Index

Snapshot 39224

Document
Trust center
URL
https://trust.worklytics.co/
Fetched
HTTP status
200
Content type
text/html
Fetch mode
browser
Size
102212 bytes
SHA-256 (raw)
c9fdbb782abbab0d9d5f1e43f8b56db09ac297a5833ac10bb86148ae1a506dcd
SHA-256 (normalized text)
0917bb16f9581620946842159ff4940415d0093b13514ab4df34f2c720066810

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Skip to navigationSkip to main content
Worklytics
Worklytics is a work analytics platform. It processes workplace metadata from your organization's tools to generate actionable insights into how your organization works and collaborates.
[email protected]
Privacy PolicyOpens in new tab
Worklytics is a work analytics platform. It processes workplace metadata from your organization's tools to generate actionable insights into how your organization works and collaborates.
This Trust Report covers security and privacy of the Worklytics platform (app.worklytics.co), which powers our Data Stream and Reports-as-a-Service offerings.
If your organization deploys our pseudonymization proxy serviceOpens in new tab, all data you send to the Worklytics platform can be sanitized within your own cloud to tokenize PII and redact any metadata fields you deem sensitive.
Nonetheless, all information security controls documented by this report apply even if you're transferring only sanitized data to the Worklytics platform.
Data InventoryOpens in new tab - list of data attributes transferred from your data sources to Worklytics for processing/storage, subject to your use-case.
Data ProtectionOpens in new tab - available data protection settings that may be configured in the Worklytics platform.
User Access ControlOpens in new tab - overview of access control for your team to the Worklyitcs platform, including supported identity providers and configurable user roles For current customers, additional compliance documentation is available via the Worklytics web application's Compliance portalOpens in new tab
Product documentation is published at docs.worklytics.coOpens in new tab.
We also encourage you to review various 3rd party assessments of our security posture:
SSL LabsOpens in new tab - A+
CryptCheckOpens in new tab - A+
Security HeadersOpens in new tab - A+
Compliance
SOC 2 Type II
SOC 2 Type I
GDPR
CCPA
Resources
View all
Current
SCO 2 Type II Report - 2026
Data Flow Diagram - Worklytics Data Stream
Network Architecture 2026-02
Penetration Test - 2026-08
Past
SOC 2 Type II Report - 2025
Penetration Test - 2024-07
SOC 2 Type II Report - 2024
Penetration Test - 2023-07
View 2 more
Controls
View all
Infrastructure security
Unique production database authentication enforced
Encryption key access restricted
Unique account authentication enforced
View 17 more Infrastructure security controls
Organizational security
Asset disposal procedures utilized
Production inventory maintained
Portable media encrypted
View 11 more Organizational security controls
Product security
Data encryption utilized
Control self-assessments conducted
Penetration testing performed
View 2 more Product security controls
Internal security procedures
Continuity and Disaster Recovery plans established
Cybersecurity insurance maintained
Configuration management system established
View 29 more Internal security procedures controls
Data and privacy
Data retention procedures established
Customer data deleted upon leaving
Data classification policy established
Data collected
Employee personally identifiable information
Workplace metadata
Customer personally identifiable information
Credit card information
Personal health information
Subprocessors
View all
Google Cloud Platform
•
cloud infrastructure
US or EU
Worklytics hosts our platform in Google Cloud Platform, using services including App Engine, BigQuery, Cloud Datastore, Cloud Storage, Compute Engine, Looker, and Pub/Sub.
Vanta and GCP Security Health Analytics continuously monitor our GCP infrastructure in real-time for compliance controls aligned to SOC 2, ISO 27001, CIS 1.1-1.5.
Customer data stored in GCP is deleted in accordance with our Data Retention Policy.
SendGrid
•
email
Worklytics uses SendGrid to send transactional email to users of our platform. This includes notifications, verifications, etc.
Limited PII (email addresses) is retained in SendGrid's logs for a short duration (~30 days).
DocSend, Inc.
•
report delivery
DocSend is used to securely deliver Reports as part of our Reports-as-a-Service offering.
Customer reports are deleted from DocSend in accordance with our Data Retention policy.