Built for teams that
can't afford a leak.
Workliq is built to process financial and operational data for analysts, research labs, and data teams. Security isn't an afterthought — it's tested by an automated tenant-isolation + injection suite on every deploy.
Six security pillars
What you get out of the box.
Tenant isolation
Every API call is scoped by `client_id` extracted from your signed JWT. Cross-tenant queries return 403 — verified by automated tests on every deploy.
Encryption everywhere
TLS 1.3 in transit. Connector credentials encrypted at rest with Fernet (rotation-ready). Disk-level encryption on the host.
Audit log
Every upload, query, ML run, share, and settings change written to an immutable audit_logs table with hashed IP, timestamp, and resource id. Exportable as CSV.
Role-based access
Workspace roles: owner / admin / analyst / viewer. A viewer can read shared datasets but cannot delete, share, or export.
No raw data to LLMs
Cloud AI providers receive your question, the dataset schema, up to 3 sample rows so the model can see how values are formatted, and the rows of the result being described — never the full dataset, and never anything outside the query you asked.
Rate limits + abuse protection
Per-client sliding-window rate limits on upload, ask, ML, and external API.
Read-only by construction
Every query — yours, or one the AI wrote — is validated before it runs. Anything that is not a SELECT is rejected: no DROP, DELETE, UPDATE, INSERT, TRUNCATE, ALTER or CREATE ever reaches your data. Stacked statements, comment injection and system-table reads are refused too. Analysis cannot modify what it analyses.
Compliance posture
Where we are, where we're going.
| Framework | Status | Notes |
|---|---|---|
| DPDP Act 2023 | aligned | Built for India. Data residency in Bangalore. |
| GDPR | aligned | DPA available for EU customers on request. |
| SOC 2 Type 1 (Planned) | planned | Drata controls being implemented. Audit target: Q4 2026. |
| SOC 2 Type 2 (Planned) | planned | After Type 1 audit pass. |
| ISO 27001 | planned | Roadmap item for enterprise customers. |
Reporting a vulnerability
Found something? Email team.workliq.ai@gmail.com. We acknowledge within 24 hours.
For enterprise security reviews (questionnaires, DPA, pen-test report), contact team.workliq.ai@gmail.com.