Trust Center
Everything your team needs to evaluate us.
Security artefacts, compliance documentation, architecture references, and data protection materials for information security, legal, and procurement reviews.
01 · Architecture
Security architecture & data flow
How Workhub is deployed inside your Microsoft 365 tenant, how data flows, and how permissions are inherited.
Available
Architecture Overview
Deployment model, data flow diagrams, and component boundaries.
Available
Identity & Access Model
How Entra ID, SharePoint, and OneDrive permissions are inherited throughout the platform.
Available
Data Flow & Residency
Where your data lives, where it's processed, and what never leaves your tenant.
Available
AI Routing & Governance
How queries are routed to Copilot, Claude, and ChatGPT. Provider contracts, data handling, training-data controls.
02 · Compliance
Compliance programme & frameworks
Our information security programme and the frameworks we map against.
Available
ISO 27001 Controls Mapping
Our controls mapped to ISO 27001 Annex A. We are actively preparing for certification.
Available
GDPR Compliance Statement
Data controller/processor model, lawful basis, subject rights, cross-border transfer safeguards.
Available
Data Processing Agreement (DPA)
Standard DPA template with Standard Contractual Clauses for GDPR-compliant processing.
In Progress
ISO 27001 Certification
Formal certification in progress. Target completion end of 2026. Interim controls mapping available now.
03 · Operational Security
Security practices & testing
How we build, test, and operate the platform securely.
Available
Penetration Test Summary
Summary of our most recent independent penetration test. Full report available under NDA on request.
Available
Vulnerability Management
SLAs for critical, high, medium patches. Dependency scanning, SAST/DAST, runtime monitoring.
Available
Incident Response Plan
24/7 response protocol, customer notification SLAs, forensics and post-mortem process.
Available
Personnel & Access
Background checks, onboarding/offboarding, least-privilege access, audit logging on internal systems.
04 · Questionnaires & Diligence
Vendor due diligence materials
Pre-filled industry-standard questionnaires and customer-specific responses on request.
Available
CAIQ (Lite)
Cloud Security Alliance Consensus Assessments Initiative Questionnaire — pre-completed.
On Request
SIG Core / SIG Lite
Standardized Information Gathering questionnaire, available pre-filled under NDA.
On Request
Custom Questionnaires
Firm-specific security and compliance questionnaires completed by our security team.
Available
Customer References
Coordinated reference calls with existing customers, on request with scheduling notice.