Worthic is a document-first accounting and finance workspace. This Security Overview summarises how Worthic protects customer accounts, workspace data, uploaded documents, document-processing workflows, and operational systems.
No online service can guarantee absolute security. Worthic uses technical and organisational controls designed to reduce risk, protect customer data, and support responsible operation of the Service.
1. Security principles
Worthic's security model is built around:
- protecting sensitive financial and administrative records;
- separating production, staging, and development environments;
- limiting human access to customer data;
- centralising staff identity, role, and access lifecycle management;
- enforcing layered protection for internal administrative access;
- promptly revoking staff sessions, trusted devices, and integrated provider access when roles or employment status change;
- maintaining auditability for sensitive administrative actions;
- using managed infrastructure providers with established security controls;
- giving workspace owners control over users, roles, and workspace membership;
- keeping customer documents and workspace content out of general AI model training unless a customer explicitly opts in.
2. Hosting and infrastructure
Worthic uses managed infrastructure providers for application hosting, database hosting, object storage, email delivery, document processing, queues, and AI-assisted workflows.
The production application and production database run on Render-hosted infrastructure. Customer documents are stored in production Cloudflare R2 object storage. Document-processing workflows run through production Cloudflare Workers and production queues. Transactional email is handled through Postmark.
Cloudflare provides Worthic's internet-facing DNS, routing, TLS, web application firewall, network-security, and zero-trust access controls. Protected production administrative entry points are gated by Cloudflare Access, and direct-origin access is restricted so that ordinary public routing cannot bypass the edge controls.
Production infrastructure uses production-specific secrets, storage, queues, and callback endpoints. Staging and development environments are separate from production and are used for testing and development work.
Material providers, including Render, Cloudflare, Google Identity Services, Google Workspace, Postmark, and other providers used by the Service, are listed in the Subprocessors List.
3. Data storage
Worthic stores structured workspace data in managed database infrastructure and stores uploaded documents in managed object storage.
Documents may include financial and administrative records such as bank statements, invoices, receipts, payslips, tax records, contracts, real estate records, investment documents, and identity or compliance documents.
Document-processing state, extraction results, review state, audit state, and derived workspace data are stored so users can review, correct, report on, and manage their records.
4. Encryption and transport security
Worthic uses HTTPS/TLS for browser and API traffic. Traffic between Worthic systems and service providers uses secure provider endpoints where supported by those providers.
Worthic relies on managed infrastructure providers for encryption at rest in database, object storage, queue, and hosting infrastructure where provider-level encryption is available. Sensitive credentials and service secrets are stored as environment-level secrets rather than in source code.
5. Account and workspace access controls
Worthic uses account authentication, session management, workspace membership, and role or permission controls to limit access to workspace data.
Where supported, Worthic may also allow Google OAuth sign-in or account linking. OAuth-based access is handled as part of Worthic's authentication controls and is subject to the same workspace membership, session, trusted-device, audit, and security-monitoring controls as other sign-in methods.
Workspace owners and administrators control who is invited into a workspace, which roles users have, and when access is removed. Users are responsible for protecting their credentials, devices, email accounts, and workspace invitations.
Worthic separates ordinary user workspace access from internal administrative access.
6. Staff identity and administrative access
Worthic uses Google Workspace as the authoritative staff identity source and Worthic Staff Access as the centralised control for staff roles, permissions, and joiner, mover and leaver lifecycle actions. Staff access is assigned to approved named identities according to least privilege and legitimate operational need.
Cloudflare Access gates protected administrative entry points at the network edge. Worthic validates Cloudflare's signed identity assertion server-side, binds the asserted email address to the authenticated Worthic staff identity, and then applies the staff member's current Staff Access role and permissions. Passing Cloudflare authentication or holding a Worthic session is not sufficient by itself: the identities must match and the Worthic staff account must remain active and authorised.
Worthic Admin access additionally requires an approved Windows or macOS device enrolled in Cloudflare WARP and Microsoft Defender for Business. The live Cloudflare policies require both the approved staff email and a platform-specific Client Certificate V2 posture check. Each approved device holds a unique certificate bound to the hardware serial number reported by Cloudflare, with client-authentication and private-key-presence requirements. Unmanaged phones, devices without the approved certificate, and certificate/serial mismatches are denied before reaching Worthic. After Cloudflare's 30-minute email-code session permits access, Worthic still requires its own login and two-factor authentication.
Staff onboarding is designed to fail closed where required identity-provider or access-provider synchronization has not completed successfully. Role changes update the staff member's Worthic permissions. Deactivation or termination revokes active Worthic sessions and trusted-device records, removes synchronized Cloudflare access, and suspends the associated Google Workspace account where the configured lifecycle policy permits.
Provider synchronization failures are retained for retry and reconciliation. Lifecycle and synchronization activity is recorded for security review, troubleshooting, compliance evidence, and incident investigation. Separate provider dashboards that are not directly integrated with Worthic Staff Access use named accounts, multi-factor authentication where available, least-privilege permissions, and periodic access review.
7. Database-level workspace isolation
Worthic uses database-level access controls, including row-level security where implemented, to help enforce separation between users, accounts, workspaces, and roles. These controls are designed to supplement application-level permission checks so that customer records are only available within the appropriate authenticated user or workspace context.
Row-level security controls are especially important for sensitive workspace data, including financial records, documents, reports, audit events, notifications, billing records, and AI-assisted processing paths. Worthic tests and reviews security-sensitive data-access paths where practical, including report-generation workflows, to reduce the risk of cross-workspace or unauthorised access.
8. Mobile access and step-up approvals
Worthic may provide mobile application access and supported OAuth sign-in using authenticated sessions, refresh-token rotation, trusted-device records, and mobile-to-web handoff flows. These controls are designed to support secure account access across supported devices while allowing users to manage sessions and trusted devices.
Worthic may use step-up approval flows or two-factor-style approval challenges for sensitive actions or higher-risk account activity. These controls are intended to add protection where risk is higher, rather than requiring two-factor approval for every login by default.
Mobile and step-up security records may include trusted-device status, session metadata, approval challenge status, timestamps, user and workspace references, IP address or technical metadata, and related audit events. These records support authentication, fraud prevention, account security, troubleshooting, and incident investigation.
Users remain responsible for protecting their devices, email accounts, OAuth accounts, passcodes, biometrics, and other authentication factors used to access Worthic.
9. Human access to customer data
Worthic limits human access to customer data. Customer documents are not routinely inspected by Worthic personnel as a support practice.
Administrative access is assigned to named staff identities, role-limited, centrally managed through Worthic Staff Access, and based on legitimate operational need. Cloudflare Access and Worthic's server-side identity binding protect supported production administrative entry points. Worthic personnel may access customer information only for authorised operational purposes, such as providing support, investigating security or reliability issues, resolving billing or account access issues, complying with legal obligations, enforcing the Terms of Service, responding to incidents, preventing abuse, or acting at a customer's request.
Worthic personnel with administrative access are subject to confidentiality obligations. Staff access, role changes, deactivation, session and trusted-device revocation, provider synchronization, and sensitive administrative activity are logged or otherwise recorded where supported, reviewed as appropriate, and retained as part of Worthic's security and compliance controls.
Admin access logs are internal by default. Customers may request information about administrative access to their workspace. Worthic may provide appropriate summaries where legally and operationally reasonable, subject to limits needed to protect security, privacy of others, confidential investigations, and abuse-prevention controls.
10. Document processing and AI
Worthic uses deterministic and AI-assisted workflows to process customer documents and workspace records.
Document-processing workflows are designed to support extraction, classification, routing, review, categorisation, and reporting. AI outputs are assistance only and must be reviewed by users before reliance.
Customer documents, customer financial data, and workspace content are not used to train third-party foundation models or general AI models without explicit opt-in consent.
11. Logging and monitoring
Worthic maintains operational logs for security, reliability, troubleshooting, compliance, and auditability. These may include:
- authentication and session logs;
- workspace access and permission events;
- administrative access logs;
- staff onboarding, role changes, deactivation, suspension, and reactivation events;
- staff session and trusted-device revocation;
- Cloudflare Access and Google Workspace synchronization, retry, reconciliation, and failure records;
- administrative identity-binding failures and unauthorised access attempts;
- security events;
- errors and diagnostics;
- document-processing state;
- background job and queue events;
- infrastructure operations.
Staff identity and access records may include the affected staff identity, action, actor or initiating process, previous and resulting state, provider synchronization result, timestamp, retry or reconciliation status, and related error or evidence reference. Failed synchronization remains visible until it is successfully reconciled or formally resolved.
12. Application error monitoring
Worthic uses application error monitoring to detect, triage, and remediate production and staging application issues. Error monitoring helps Worthic identify failed requests, unhandled exceptions, release-specific regressions, and operational problems that could affect service reliability, security, or customer workflows.
Error-monitoring records may include exception details, stack traces, release identifiers, environment tags, affected routes, request metadata, device or browser metadata, and other diagnostic information needed for troubleshooting. Worthic configures error monitoring to avoid intentional collection of secrets, passwords, payment credentials, authentication tokens, full customer documents, or unnecessary customer financial content.
Where error-monitoring events contain personal information or customer-related metadata, that information is treated as operational and security data and is handled under Worthic's privacy, confidentiality, access-control, and retention practices.
Logs are retained for operational, security, legal, and compliance purposes and are protected from ordinary workspace users.
13. Backups, deletion, and retention
Worthic maintains operational backups, logs, and infrastructure records to support continuity, recovery, security, legal obligations, and incident investigation.
If a workspace is deleted, Worthic retains workspace data and documents for 14 days to allow export and recovery. After that period, production data is scheduled for deletion or de-identification, subject to limited retention in backups, logs, audit records, billing records, security records, legal holds, and compliance records.
Backups and logs may persist for a limited period after production deletion and are then deleted or overwritten according to operational schedules.
14. Incident response
Worthic handles suspected security incidents through an incident response process that includes detection, triage, containment, impact assessment, remediation, and post-incident review.
Incidents involving personal information or customer content are assessed for legal, contractual, customer-notification, and regulator-notification obligations.
A suspected staff-account compromise, unauthorised role change, failed termination, stale provider access, identity-binding failure, or failure to suspend or remove a deactivated staff identity is treated as a potential security incident. Containment may include deactivating the staff record, revoking Worthic sessions and trusted devices, removing Cloudflare access, suspending the Google Workspace account, rotating affected credentials or tokens, and restricting protected administrative routes. Recovery includes verification that identity binding, role enforcement, synchronization, retry, and reconciliation controls are functioning before access is restored.
15. Vulnerability management
Worthic uses code review, GitHub security alerts, dependency maintenance, code scanning where enabled, CI dependency audit checks, environment separation, provider-level monitoring, and operational hardening to reduce security risk.
Security-relevant issues are prioritised based on severity, exploitability, customer impact, and exposure of customer data or production systems.
Worthic tracks applicable vulnerabilities in a vulnerability and remediation register and applies target remediation timeframes based on severity. Critical and high vulnerabilities are prioritised for prompt mitigation or remediation, and vulnerabilities that may involve unauthorised access, exposed secrets, customer data, or production compromise are handled through the incident response process.
Automated scanning includes Semgrep static analysis and production dependency-audit gates for the web and mobile applications. Scans run on relevant changes, weekly, and on demand. Error-severity Semgrep findings and high/critical production dependency findings block the applicable workflow. Scan reports, manifests, summaries, and logs are retained as audit evidence, and material findings and risk acceptances are tracked in the vulnerability register. Worthic separately maintains a runtime and end-of-life register for supported technology lifecycle review.
16. Customer responsibilities
Customers are responsible for:
- using strong credentials;
- protecting devices and email accounts;
- configuring workspace permissions carefully;
- removing users who no longer require access;
- reviewing imported, extracted, and AI-assisted outputs before reliance;
- exporting data before deletion where needed;
- complying with laws that apply to their records, users, and workspaces.
17. Updates
Worthic updates this Security Overview as its infrastructure, controls, subprocessors, or security practices change.