WorkplaceCodex

Security and compliance

Last updated: October 2026

Security is a design principle of the Workplaced platform. This page describes the key organisational and technical measures.

Certification

Workplaced is ISO 27001 certified (certificate 0202968). The information security management system is audited internally and externally on a regular basis.

Access and authorisation

Access to the platform is by invitation only; there is no open registration. Authorisation is enforced in the database: every data request is checked against the requester's role and organisation. Anyone who is not a member of an organisation sees nothing.

Platform operator rights are granted only through a managed allowlist, never through the user interface.

Data protection

Data is encrypted in transit (TLS) and at rest. Customer data is logically separated per organisation. Measurement results are shown only in aggregated form; individual responses cannot be consulted by the organisation.

Availability and recovery

The platform runs on redundant infrastructure with automatic backups. Recovery procedures are tested periodically.

Breaches and incidents

Suspected data breaches are investigated following a fixed procedure and, where the GDPR requires, reported to the affected organisations and the supervisory authority without undue delay.

Report a vulnerability

Found a security vulnerability? Report it via customer@workplaced.com. We appreciate responsible disclosure and respond quickly.

Questions about this document? Email customer@workplaced.com.