Security & Compliance

Built for teams that
can't afford a leak.

Workliq is built to process financial and operational data for analysts, research labs, and data teams. Security isn't an afterthought — it's tested by an automated tenant-isolation + injection suite on every deploy.

Six security pillars

What you get out of the box.

🛡

Tenant isolation

Every API call is scoped by `client_id` extracted from your signed JWT. Cross-tenant queries return 403 — verified by automated tests on every deploy.

🔒

Encryption everywhere

TLS 1.3 in transit. Connector credentials encrypted at rest with Fernet (rotation-ready). Disk-level encryption on the host.

📜

Audit log

Every upload, query, ML run, share, and settings change written to an immutable audit_logs table with hashed IP, timestamp, and resource id. Exportable as CSV.

👥

Role-based access

Workspace roles: owner / admin / analyst / viewer. A viewer can read shared datasets but cannot delete, share, or export.

🚫

No raw data to LLMs

Cloud AI providers receive your question, the dataset schema, up to 3 sample rows so the model can see how values are formatted, and the rows of the result being described — never the full dataset, and never anything outside the query you asked.

🚦

Rate limits + abuse protection

Per-client sliding-window rate limits on upload, ask, ML, and external API.

🔒

Read-only by construction

Every query — yours, or one the AI wrote — is validated before it runs. Anything that is not a SELECT is rejected: no DROP, DELETE, UPDATE, INSERT, TRUNCATE, ALTER or CREATE ever reaches your data. Stacked statements, comment injection and system-table reads are refused too. Analysis cannot modify what it analyses.

Compliance posture

Where we are, where we're going.

FrameworkStatusNotes
DPDP Act 2023alignedBuilt for India. Data residency in Bangalore.
GDPRalignedDPA available for EU customers on request.
SOC 2 Type 1 (Planned)plannedDrata controls being implemented. Audit target: Q4 2026.
SOC 2 Type 2 (Planned)plannedAfter Type 1 audit pass.
ISO 27001plannedRoadmap item for enterprise customers.

Reporting a vulnerability

Found something? Email team.workliq.ai@gmail.com. We acknowledge within 24 hours.

For enterprise security reviews (questionnaires, DPA, pen-test report), contact team.workliq.ai@gmail.com.

More reading

We use essential cookies for login and security. Optional cookies improve product analytics (Sentry session replays, page-view counts). You can decline — the product still works. Privacy details.