Legal · Compliance landing page
Security
Last updated: April 29, 2026
AIWorkFluency’s value proposition is audit-grade evidence of training. That depends entirely on the data integrity and confidentiality of the system that produces it. This page describes how we operate. We update it as the platform evolves.
Data residency
All customer data — accounts, training records, the Compliance Folder — is processed and stored on infrastructure located in the European Economic Area. Sub-processors that operate outside the EEA are bound by Standard Contractual Clauses (Commission Decision 2021/914) supplemented with appropriate technical measures.
Encryption
- In transit: TLS 1.2 minimum (TLS 1.3 preferred) for all connections, including the database and email layer. HSTS enforced; HTTP redirected to HTTPS.
- At rest: AES-256 encryption on the primary database and on all backups.
- Secrets: API keys and SMTP credentials are stored only in environment variables on the production host, never in source control.
Access control
- Production access is restricted to named individuals on a strict least-privilege basis.
- Multi-factor authentication is enforced on administrator accounts wherever supported by the provider — including Supabase, the hosting console, the email provider, and source control.
- Customer admins can only access their own organisation’s data via the dashboard. Row-level security policies are enforced at the database layer.
- Production access is logged and reviewed at least quarterly.
Sub-processors
| Sub-processor | Function | Region |
|---|---|---|
| Supabase | Application database, authentication | EU (Frankfurt) |
| Resend | Transactional email delivery | EU / US (SCCs in place) |
| Hosting provider | Application server | EU |
| Anthropic (Claude API) | Internal lesson-content generation only — no employee/customer PII transmitted | US (SCCs in place) |
| Google (Gemini API) | Internal lesson-content generation only — no employee/customer PII transmitted | EU / US (SCCs in place) |
A signed copy of the sub-processor list is provided to enterprise customers on request.
Backups and recovery
- Daily automated database snapshots, retained for 30 days.
- Weekly full backups, retained for 90 days.
- Backups are encrypted with the same standard as the primary store and tested for restorability quarterly.
Incident response
We will notify affected customers of any personal data breach within 72 hours of detection, in accordance with GDPR Article 33. The notification will describe the nature of the breach, the categories and approximate volumes of data affected, the likely consequences, and the remedial measures taken or planned.
Vulnerability disclosure
If you believe you have found a security vulnerability, please email daniel.rozsa@aiworkfluency.com with reproduction steps. We aim to acknowledge within 2 business days and remediate critical issues within 14 days. We do not pursue legal action against good-faith researchers.
Compliance roadmap
- SOC 2 Type II: target Q4 2026.
- ISO/IEC 27001: target H2 2027.
- Article 4 self-assessment: reviewed quarterly against AI Office and national-authority guidance.
Current status, gaps, and target dates are disclosed honestly to any enterprise customer on request.
Data Processing Agreement
A counter-signed Data Processing Agreement is included in every customer contract and is also available standalone on request.