Subworkit Security
The security of your data and account is a top priority at Subworkit. We implement industry-standard security controls across all layers of the platform — from network transport to database storage to application-level access controls.
Technical Security Controls
- Encryption in Transit — all data transmitted between your device and Subworkit servers is encrypted with TLS 1.3
- Encryption at Rest — database and file storage is encrypted with AES-256
- Password Hashing — passwords are hashed with bcrypt — we never store or transmit plaintext passwords
- Two-Factor Authentication — enable 2FA via SMS or authenticator app for additional account protection
- Role-Based Access Controls — strict permission enforcement limits data access to authorized users and roles only
- Audit Logging — all sensitive account and financial actions are logged with timestamps for review
- OWASP Top 10 — development practices follow OWASP Top 10 guidelines for web application security
Responsible Disclosure
If you discover a security vulnerability in the Subworkit platform, please report it responsibly to our security team via the contact page. We respond to security reports within 72 hours per GDPR Article 33 requirements and will acknowledge and remediate confirmed vulnerabilities promptly.
Compliance
Subworkit complies with GDPR (EU), CCPA (California), and applicable US data protection regulations. See our Privacy Policy and GDPR Rights page for full details.