Legal
Security & Compliance
Last updated: September 22, 2026
Your callers share private things with Emma. Here is exactly how we protect that — and where we are on certifications. We say what is true today, not what we plan to be.
Where we stand
| Standard | Status |
|---|---|
| HIPAA | In progress. Workky is not yet a HIPAA business associate and does not offer a BAA. Healthcare businesses handling PHI cannot onboard until this is complete. |
| SOC 2 | Not started. Our infrastructure vendors (AWS, Twilio, Stripe, OpenAI, Google, Anthropic) each maintain SOC 2 Type II or equivalent audits. |
| CCPA / CPRA | Compliant. See our Privacy Policy. |
| California call recording & bot disclosure | Compliant. Emma discloses AI status and recording on every call. |
| TCPA / carrier messaging rules | Compliant. Transactional SMS only, with logged consent and STOP handling. |
| PCI DSS | Card data is handled by Stripe (PCI Level 1). Workky never stores card numbers. |
How we protect data
Encryption. All data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256 on Amazon Web Services.
Access control. Every Workky CRM user has an individual login. Role-based permissions let you decide who sees recordings, transcripts, and contacts. Workky staff access to customer data requires multi-factor authentication and is limited to support and engineering on a need-to-know basis, and is logged.
Data separation. Each customer's CRM data is logically isolated. No customer can see another customer's data.
No AI training on your data. Call recordings, transcripts, and CRM records are never used to train or improve AI models. Our AI vendors (OpenAI, Google, Anthropic) process data under business terms that prohibit training on it.
Retention you control. Recordings and transcripts are kept 90 days by default. Change it in settings. Export or delete your data any time.
Infrastructure. Hosted on AWS in the United States with automated backups. Telephony and SMS through Twilio. Payments through Stripe.
Vendor review. We review every subprocessor's security posture before adding it. The current list is at workky.ai/subprocessors and we notify customers before adding a new one.
Incident response. If a security incident affects your data, we will notify you without undue delay and within 72 hours of confirming it, with what happened and what we are doing.
Security & Compliance FAQ
Do you sign a Business Associate Agreement (BAA)? Not yet. HIPAA readiness is in progress. Until then, Emma cannot be used for PHI. Contact legal@workky.ai to be notified when BAAs are available.
Is Workky SOC 2 certified? No. We rely on audited vendors for infrastructure and will publish our own audit status here when we begin one.
Is my data used to train AI? Never. Not by Workky, not by our vendors.
Where is my data stored? In the United States, on AWS.
Can I export or delete my data? Yes. Export from Workky CRM at any time. Account deletion removes your data within 30 days (backups within 90 days).
Who can hear my call recordings? Only users you authorize in Workky CRM, and Workky staff when you request support.
What happens to my data if I cancel? You have 30 days to export. Then it is deleted.
Do you perform penetration testing? Not yet on a formal cadence. We run automated vulnerability scanning and will publish our testing schedule as the company grows.
Can I get a security questionnaire completed? Yes. Email legal@workky.ai.
Questions about this page?
Email hello@workky.ai