Security overview
A clear summary of Workforce AI security practices and independent assurance.
- Scope
- Product security overview
- Reviewed
- 2026-07-11
Security, privacy, and assurance
Review how Workforce AI protects customer data, see independent assurance and accessibility records, check current service health, and request the documents your team needs.
Start your review
Open security, privacy, legal, HIPAA, accessibility, and subprocessor information directly.
A clear summary of Workforce AI security practices and independent assurance.
How Workforce AI collects, uses, protects, retains, and shares information.
The terms that govern use of Workforce AI.
Privacy and data-processing commitments for customer agreements.
The service providers Workforce AI uses and the work they support.
How Workforce AI supports approved healthcare workflows and BAA requests.
Plain-language information about business associate agreements and how to request one.
Workforce AI accessibility conformance report based on VPAT 2.5Rev and covering Revised Section 508.
Assurance at a glance
Each item names the scope and source so a reviewer can understand exactly what it covers.
Workforce AI completed an independent SOC 2 Type II examination covering the Security trust services criteria for the period July 3 through October 3, 2025. The confidential report is available to qualified reviewers by request.
Workforce AI supports HIPAA-aligned deployments for approved healthcare workflows and can provide a business associate agreement after reviewing the intended use and configuration.
Workforce AI publishes a VPAT-based Accessibility Conformance Report covering WCAG 2.0 and the Revised Section 508 standards. The report is available directly from this trust center.
Workforce AI does not use customer business content to train shared AI models.
Workforce AI encrypts data in transit with TLS 1.2 or higher, encrypts data at rest with AES-256, and separates customer data by account.
The trust center checks the public website, account dashboard, API health endpoint, support center, and scheduling service and displays the current result on the status page.
Frequently reviewed
Yes. Submit a document request with your business email and review purpose. Approved requests receive an expiring access link that Workforce AI can revoke when the review is complete.
HIPAA does not have a general government-issued product certificate. Workforce AI maintains a HIPAA compliance program, supports approved healthcare workflows, and can provide a business associate agreement after reviewing the intended use and configuration.
A business associate agreement is a HIPAA contract used when a service provider may handle protected health information for a covered organization. It explains permitted use, safeguards, breach reporting, subcontractor duties, and what happens to the data when the relationship ends.
Yes. Workforce AI publishes an Accessibility Conformance Report based on VPAT 2.5Rev that covers WCAG 2.0 and the Revised Section 508 standards.
The Workforce AI security team reviews the request, confirms the business purpose, and either approves it, asks a follow-up question, or explains why it cannot be provided. Approved confidential reports receive expiring access; agreement requests move to the appropriate review and signature step.
Keep your review moving
Requests go directly to the Workforce AI security team and receive an email confirmation.