Security

This page describes how WorkSage protects user data, including our infrastructure, encryption, access controls, audits, and incident response.

1. Data principles

WorkSage does not train AI models on user data. Sage uses retrieval-augmented generation to answer from your private context store, and passes only the context needed at inference time to language model providers, who are contractually prohibited from retaining or training on it.

WorkSage does not sell user data.

Users retain ownership of their data and can export it at any time. On cancellation, data remains available for export for 30 days before permanent deletion.

Spaces are isolated at the storage layer. Data does not cross between Spaces. Cross-Space queries operate on metadata only, not content.

2. Infrastructure

WorkSage runs on Google Cloud Platform, which provides underlying compute, storage, and networking with independent certifications including ISO 27001 and SOC 2 Type II.

3. Encryption

All data in transit is encrypted using TLS 1.2 or higher. All data at rest is encrypted using AES-256.

4. Authentication and access

WorkSage connects to third-party services via OAuth. No passwords are stored. Users can revoke access at any time from the underlying service.

Multi-factor authentication is available on all WorkSage accounts.

WorkSage requests the minimum permissions required for each feature.

5. Audits and certifications

WorkSage is CASA-certified at Tier 2 (Cloud Application Security Assessment), a third-party security audit based on the OWASP Application Security Verification Standard, renewed annually.

WorkSage undergoes third-party penetration testing of the application and infrastructure.

6. Employee access

WorkSage employees do not have general access to user data. Case-by-case access is granted only to designated technical personnel, only when required to respond to a support request or production incident, and is logged.

7. Incident response

WorkSage maintains a documented incident response process covering detection, containment, investigation, and resolution. Affected users are notified in accordance with applicable law and any Data Processing Agreement in place.

8. Backups and recovery

Data is backed up regularly.

  • Recovery Time Objective (RTO): 4 hours
  • Recovery Point Objective (RPO): 1 hour

9. Enterprise controls

Enterprise plans include additional security controls:

  • Single Sign-On via your identity provider, including Google Workspace and Microsoft Entra ID
  • Audit logs covering workspace activity, access events, and integration changes
  • Data residency configurable at contract time
  • Custom controls tailored to specific security or compliance requirements
  • Dedicated support with a named account contact and priority response SLA

See the Enterprise page →

10. Service status

Current and historical uptime is published at uptime.worksage.ai/status/worksage.

11. Reporting a vulnerability

Suspected security vulnerabilities should be reported to security@worksage.ai. Reports are acknowledged within one business day.

WorkSage does not currently operate a paid bug bounty programme.

12. More

Last updated: March 2026

One intelligence layer,
everywhere you work.