Legal
Security
Last updated: 16 June 2026
ProjectWorks.ai is built for professional project delivery teams, including agencies and enterprises that handle sensitive commercial and operational data. This page summarizes our security practices. It is intended as an overview — not a contractual commitment unless referenced in an order form or DPA.
Enterprise customers may request a security questionnaire, subprocessor list, or custom security addendum by contacting security@projectworks.ai.
1. Security principles
- Defense in depth across infrastructure, application, and organizational layers
- Least-privilege access for employees and service accounts
- Tenant isolation for workspace and project data
- Secure development practices and dependency monitoring
- Incident detection, response, and customer notification where required
2. Infrastructure
- Hosted on reputable cloud providers with industry-standard physical and network security
- Encryption in transit via TLS 1.2+ for all web and API traffic
- Encryption at rest for database storage provided by our cloud infrastructure
- Network segmentation and restricted database access from application services only
- Automated backups for disaster recovery with defined retention periods
3. Authentication and identity
- Authentication managed through Clerk with industry-standard session handling
- Support for email/password and social login on standard plans
- Enterprise SSO via SAML/OIDC (Google Workspace, Microsoft Entra ID) on eligible plans
- SCIM 2.0 user provisioning and deprovisioning for automated lifecycle management (Agency / Enterprise)
- Role-based access control (RBAC) within workspaces and projects
4. Application security
- Row-level security (RLS) policies on tenant-scoped database tables
- Server-side authorization checks before data access, including API routes
- API rate limiting to mitigate abuse and credential stuffing
- Webhook signature verification for billing and identity events
- Audit logging for governance actions on eligible enterprise plans
- Content Security Policy and security headers on web responses
5. AI and data processing security
- AI requests scoped to authenticated users with project-level access checks where applicable
- Prompts sent to AI subprocessors contain only the content necessary to fulfill the requested feature
- Demo mode (/try/*) uses isolated sample data and does not write to production workspaces
- We configure AI providers, where available, not to train on Customer Content for public models
See Data Handling for retention and processing details.
6. Organizational security
- Access to production systems limited to authorized personnel on a need-to-know basis
- Multi-factor authentication required for administrative access
- Security awareness for team members handling customer data
- Vendor review for subprocessors handling personal or confidential data
7. Vulnerability management
- Dependency scanning and timely patching of critical vulnerabilities
- Responsible disclosure program for security researchers
- Periodic review of authentication, authorization, and tenant boundary controls
Report vulnerabilities to security@projectworks.ai. Please include steps to reproduce and avoid accessing data belonging to other customers.
8. Incident response
We maintain procedures to investigate, contain, and remediate security incidents. Where required by law or contract, we will notify affected customers without undue delay after confirming a breach of personal data.
9. Compliance roadmap
We align our program with common enterprise expectations (SOC 2-style controls, GDPR, and industry best practices). Formal certifications, if pursued, will be listed here and in customer documentation. Contact us for current status.
10. Your responsibilities
- Use strong passwords and enable SSO/MFA where available
- Manage user access and promptly revoke departed team members
- Classify and limit sensitive data uploaded to the Service
- Review AI outputs before use in regulated or safety-critical contexts