Skip to content

Security & privacy

This page summarises the main security and privacy controls built into Workable. It is intended to help you understand how we aim to protect your data and privacy in practice.

We do not share your data with third-parties except as defined in our Privacy policy.

We do not use remote fonts or other potential usage trackers that could identify you or track your behaviour in the web app at https://go.work-able.app or in backend services.

We use privacy-focused Cloudflare Web Analytics to obtain usage analytics for service performance and feature improvement. Cloudflare Web Analytics does not use any client-side state, such as cookies or localStorage, to collect usage metrics. Cloudflare Web Analytics does not “fingerprint “individuals via their IP address, User Agent string, or any other data for the purpose of displaying analytics. For more information: https://www.cloudflare.com/en-au/web-analytics/

We store the minimum required amount of data in local cookies / local storage to support:

  • Secure authentication and access control
  • Personal preferences i.e. preferred time units, theme, and user interface language
  • Cached organisation and plan data to provide limited offline support (e.g. viewing plans during a network interruption) and a responsive user experience

When you logout:

  • Browser local storage data is deleted
  • Personal preference settings for the web app are retained i.e. preferred time units, theme, and user interface language. If necessary you can manually delete these in your web browser Inspector panel.

Operational logs are captured for the following events:

  • Sensitive account actions: for traceability. This includes logs of team membership actions, subscription & billing changes, and data exports performed by team members. These are available for viewing by Organisation Administrators in Settings → Activity log. If the organisation is deleted, this data is also deleted immediately.

  • Scheduler job performance: limited data about requested and completed plan scheduling tasks are logged to support performance analysis and improvement, and to mitigate system abuse by malicious users. Data captured includes organisation ID, job ID, scheduling outcomes, and job durations. This data is only accessible to system administrators with authenticated access and for security reasons persists even if your organisation account is deleted.

  • Subscription and billing actions: Subscription and billing data is managed by Stripe, Inc. who may log data for security and performance reasons. Refer to the Stripe Privacy Policy.

Workable is designed to protect your data in transit and at rest with encryption:

  • HTTPS / SSL / TLS is used between your browser and the platform
  • Internal platform connections are protected with SSL, and the database(s) provide encryption in transit and at rest
  • HTTP Strict Transport Security (HSTS) is applied

Workable uses passwordless authentication rather than storing user passwords. This process incorporates:

  • Email verification during sign-up and before an account is activated
  • “Magic link” sign-in with a one-time verification code
  • Short-lived authentication links and codes
  • Secure random token generation for authentication flows
  • Constant-time verification for login code checks
  • JWT-based API authentication with token expiry
  • Account protection on login requests

Endpoints are rate limited to reduce brute-force and abuse attempts.

Authorisation and organisation data boundaries

Section titled “Authorisation and organisation data boundaries”

Workable is a multi-tenant application. Keeping data separated between organisations is a core security requirement. Workable uses both application-level authorisation and database-level isolation to prevent cross-organisation data access

  • Role-based access control defines what a Viewer, Contributor, Org Admin, and Billing Manager can do
  • Permission checks verify authentication and required permission level
  • Organisation membership checks ensure a user can only act within organisations they belong to
  • Server-side permissions enforcement
  • Forced Row-Level Security is enabled on multi-tenant database tables

Workable includes controls to reduce the chance that malicious or malformed input reaches sensitive logic or storage:

  • Schema validation is applied to API payloads and stored structures
  • Request size limits are applied on larger endpoints such as scheduler requests
  • Safe structure parsing includes checks for dangerous keys
  • String sanitisation and HTML escaping are used to reduce XSS and injection risks
  • Server-side feature enforcement limits the potential for manipulating requests
  • Input constraints are applied

Workable is designed to minimise unnecessary exposure of sensitive data:

  • Organisation data is segregated so users only access organisations they belong to
  • Least-privilege access is applied through roles
  • Passwords are not used or saved during normal sign-up or sign-in
  • Payment details are handled through secure Stripe-hosted flows rather than data collection and storage inside Workable
  • Data exports and destructive actions are restricted to authorised roles

Workable includes technical safeguards, but secure operation also depends on organisation administrators and users using the platform carefully.

Recommended practices:

  • Keep the number of Organisation Administrators limited to trusted users
  • Review member roles regularly and remove access that is no longer needed
  • Transfer the Billing Manager role only when necessary and to the correct administrator
  • Treat exported data files as sensitive
  • Use verified email accounts and secure mailbox access
  • Log out when you have finished using the web app