Security & Compliance

Built for teams that
can't afford a leak.

Workliq processes financial and operational data for CA firms, R&D labs, and SaaS RevOps teams. Security isn't an afterthought — it's tested on every deploy and audited every quarter.

Six security pillars

What you get out of the box.

🛡

Tenant isolation

Every API call is scoped by `client_id` extracted from your signed JWT. Cross-tenant queries return 403 — verified by automated tests on every deploy.

🔒

Encryption everywhere

TLS 1.3 in transit. Connector credentials encrypted at rest with Fernet (rotation-ready). Disk-level encryption on the host.

📜

Audit log

Every upload, query, ML run, share, and settings change written to an immutable audit_logs table with hashed IP, timestamp, and resource id. Exportable as CSV.

👥

Role-based access

Workspace roles: owner / admin / analyst / viewer. A viewer can read shared datasets but cannot delete, share, or export.

🚫

No raw data to LLMs

Cloud AI providers only receive your natural-language question + dataset schema for that single query — never the raw rows.

🚦

Rate limits + abuse protection

Per-client sliding-window rate limits on upload, ask, ML, and external API. SQL Guard blocks non-SELECT statements, injection attempts, system table reads.

Compliance posture

Where we are, where we're going.

FrameworkStatusNotes
DPDP Act 2023compliantBuilt for India. Data residency in Bangalore.
GDPR-alignedcompliantDPA available for EU customers on request.
SOC 2 Type 1in progressDrata controls being implemented. Audit target: Q4 2026.
SOC 2 Type 2plannedAfter Type 1 audit pass.
ISO 27001plannedRoadmap item for enterprise customers.

Reporting a vulnerability

Found something? Email security@workliq.me. We acknowledge within 24 hours.

For enterprise security reviews (questionnaires, DPA, pen-test report), contact hello@workliq.me.

More reading

We use essential cookies for login and security. Optional cookies improve product analytics (Sentry session replays, page-view counts). You can decline — the product still works. Privacy details.