Snapshot 48325
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Skip to content Security Revised: Oct 5, 2026 We know that security is crucial to you, and it's our top priority. Workzone exercises great care to secure your company's confidential information. Workzone uses multi-layered security to protect your data, and we are continuously engaged in examining and updating security as we update our service. Workzone is SOC 2 Type II compliant. On the Enterprise plan, Workzone supports HIPAA compliance and signs a Business Associate Agreement (BAA). Customer data is encrypted in transit and at rest, backed up hourly to a secure off-site facility, and protected by annual penetration testing. Administrators control access with single sign-on (SSO), multi-factor authentication (MFA), and detailed activity logs. Reviewing Workzone for your security team? Visit the Workzone Trust Center to see our live security controls and request our SOC 2 Type II report, BAA, HECVAT, and VPAT. Internally, we restrict access to all confidential personal and company information to employees who need access to the information in order to do their jobs. These employees are limited in number and are committed to our privacy and security policies. All employees and contractors sign confidentiality agreements, and all employees pass a background check and complete security awareness training when they join and every year after. Any employee who violates our privacy and/or security policies is subject to possible termination and civil and/or criminal prosecution. We do not reveal any personally identifiable information that we collect about you, your use of Workzone, or any information that you post to anyone else. We will not sell, rent, or release any personal or company information to any other party without your explicit consent, unless required by law. We provide state-of-the-art security to protect your personal and company information, and we devote significant resources to continually develop and enhance the security of Workzone and your information. Compliance and Certifications SOC 2 Type II Workzone is SOC 2 Type II compliant. A SOC 2 Type II audit tests whether security controls operate effectively over a period of time, and it is the standard most IT, security, and procurement teams ask for when reviewing a vendor. You can request access to our SOC 2 Type II report in the Workzone Trust Center. HIPAA and Business Associate Agreements On the Enterprise plan, Workzone supports HIPAA compliance and signs a Business Associate Agreement with your organization. Hospitals, health systems, medical groups, and dental groups use Workzone Enterprise to manage projects that may involve protected health information (PHI) in one secure, governed place. Our BAA is available to review in the Workzone Trust Center. HECVAT and VPAT Colleges and universities can skip the back-and-forth on vendor reviews. Our completed Higher Education Community Vendor Assessment Toolkit (HECVAT v4.1.6) and our Voluntary Product Accessibility Template (VPAT 2.5, Revised Section 508 edition) are both available in the Workzone Trust Center. Workzone Trust Center The Workzone Trust Center shows the security controls behind Workzone, monitored continuously and updated automatically. It covers more than 60 controls across infrastructure security, organizational security, product security, internal security procedures, and data privacy. It is also where you can request our compliance reports and security documentation. Physical Security Our secure hosting facility is equipped with state-of-the-art security features. Access to the servers requires a security badge, PIN number, and sign-in at the front desk. The facility has extensive 24/7 video surveillance and a monitored alarm system. In addition, a key is required to access a locked cabinet that houses the password-protected servers. Firewall and Monitoring Workzone employs a highly secure firewall that blocks all outside access to the servers except for HTTP, HTTPS, and SSH. Public SMTP is blocked, so email viruses cannot propagate through our network. Public FTP is also blocked so it cannot be compromised. The servers on which Workzone sites reside are continuously monitored for attempted network attacks on a 24/7 basis, using sophisticated software tools. Formal vulnerability management and system monitoring procedures govern how issues are found and fixed, and anti-malware protection is deployed, logged, and kept up to date on all relevant systems. Operating System Security Workzone enforces tight operating system-level security by using a minimal number of access points to all production servers. We protect all system accounts with passwords and follow best practices for periodically modifying them. All operating systems and applications are maintained at each vendor's recommended patch levels for security. Privileged access to production systems, databases, the network, the firewall, and encryption keys is restricted to authorized staff with a business need. Access to production databases requires unique, secure authentication such as an SSH key, and access is revoked promptly when an employee leaves the company. Application Security All data transmissions are protected via 256-bit financial-grade encryption. The lock icon in the browser indicates that your data is fully secure while in transit over the internet. Datastores that house sensitive customer data are also encrypted at rest. Each Workzone user must log in with an individual user ID and password. When you enter your password to log in to Workzone, your password is encrypted as it travels across the internet, so it cannot be intercepted. Too many failed password attempts will temporarily lock the account until the user resets their password. Folders and individual files can be locked (hidden), so that only authorized users can view specific information. Additionally, each user is assigned one of five roles (Administrator, Manager, Contributor, Reviewer, or Partner), which defines their level of authority within the system. Reviewers and Partners get the simplest view, designed for outside stakeholders who only need to review and approve work. Workzone is penetration tested at least once a year, and identified vulnerabilities are remediated according to defined timelines. New code follows a formal software development life cycle that governs how changes, including emergency changes, are built, tested, and released. Access Controls and Authentication Administrators manage these settings from the Security page under Global settings, and the settings apply across all workspaces. Single sign-on (SSO). Connect Workzone to your identity provider using SAML. Workzone provides setup guides for Active Directory Federation Services (ADFS) and Okta, with guidance for other providers such as Azure, Shibboleth, and Ping. You can require SSO for all users, or only for your internal email domains while external partners log in with an email address and password. Google and Microsoft login. On every plan, users can sign in with their Google or Microsoft accounts once your IT team approves Workzone for that type of authentication. Multi-factor authentication (MFA). Administrators can set MFA to Optional or Required. Users verify their identity with a code from an authenticator app or a secondary email address. Administrators can reset a user's MFA setup at any time. Automatic logout. Sessions time out after 60 minutes of inactivity, or after one week, depending on your site's setting. When SSO is enabled, your identity provider controls the session. Expiring passwords. Require every user to change their password every 90 days. Expiring user IDs. Automatically disable any account that has not logged in within 30 days. An Administrator can reactivate the account at any time. Disable user-specific cookies. Prevent Workzone from saving login information so every user must log in manually each time. Activity Logs Every Workzone plan automatically records user activity in Activity Logs. Each entry includes the user name, the date and time, the event category, a description of the event, and the IP address where available. Logged events include logins and logouts, uploads, downloads, deletions, document edits, comments, folder changes, user changes, approval responses, and administrator "log in as user" sessions. Logs can be filtered by date range, user, document, or event, so you can quickly answer who changed what, and when. System Redundancy The Workzone system is designed for 24x7x365 operation. It features built-in redundancy, including redundant access to multiple internet backbones, redundant power protection via both battery backup and a high-power emergency generator, and a sophisticated climate control system. Workzone maintains documented business continuity and disaster recovery plans and tests them at least once a year. We also carry cybersecurity insurance. Backup All customer data is automatically backed up hourly and stored at a secure, off-site facility. Data Retention and Deletion Workzone follows formal data retention, disposal, and data classification policies so confidential information stays restricted to authorized personnel. When a customer leaves Workzone, we remove their confidential data from the application environment. Enterprise Security Organizations with advanced security and compliance requirements run Workzone on the Enterprise plan, which includes: HIPAA support with a signed BAA Single sign-on (SSO) Multi-factor authentication (MFA) 5 free collaborators per core user, plus unlimited free guests and reviewers Enterprise pricing is custom. Contact us for a quote and a walkthrough with your IT team. Frequently Asked Questions Is Workzone SOC 2 compliant? Yes. Workzone is SOC 2 Type II compliant. You can request access to the report in the Workzone Trust Center at trust.workzone.com. Is Workzone HIPAA compliant? Yes, on the Enterprise plan. Workzone supports HIPAA compliance and signs a BAA for organizations that handle protected health information. Will Workzone sign a Business Associate Agreement (BAA)? Yes. Workzone signs a BAA with Enterprise customers. You can review the BAA in the Workzone Trust Center. Does Workzone encrypt data at rest? Yes. Datastores that house sensitive customer data are encrypted at rest, and all data in transit is protected with 256-bit encryption. Does Workzone perform penetration testing? Yes. Workzone is penetration tested at least once a year, and vulnerabilities are remediated according to defined timelines. Does Workzone have a HECVAT or VPAT? Yes. Our completed HECVAT v4.1.6 and VPAT 2.5 are available in the Workzone Trust Center at trust.workzone.com. Does Workzone support single sign-on? Yes. Workzone supports SSO using SAML on the Enterprise plan, with setup guides for ADFS and Okta and guidance for providers such as Azure, Shibboleth, and Ping. Does Workzone support multi-factor authentication? Yes. Administrators can make MFA optional or required, and users verify with an authenticator app or a secondary email address. MFA is available on the Enterprise plan. Does Workzone keep an audit trail? Yes. Activity Logs are included on every plan and record logins, uploads, downloads, deletions, edits, comments, and user changes, along with the user, date, time, and IP address. How is my data protected? Customer data is encrypted in transit and at rest, backed up hourly to a secure off-site facility, and protected by annual penetration testing. Servers sit behind a firewall that allows only HTTP, HTTPS, and SSH, with 24/7 monitoring for attempted attacks. How do I request Workzone's security documentation? Visit the Workzone Trust Center to request our SOC 2 Type II report, BAA, HECVAT, and VPAT. For help with a security questionnaire, contact us. Contacting Workzone If you have any questions about Workzone security or privacy procedures, please contact us. To request our compliance reports and security documentation, visit the Workzone Trust Center. Workzone Customer Service<br> 651 E Township Line Road, #1427<br> Blue Bell, PA 19422<br> 610-275-9861