Technology & Security.

The Workzoom technology platform, architecture and security by the receipt: hosting, encryption, certifications, and response SLAs, all on this page.

Platform receipt

Workzoom is a cloud-based platform built on a proprietary multi-tier Java architecture, hosted on Amazon Web Services data centers in Canada and the United States. Every client has an isolated database schema and document repository. Below: every security signal, the SLA, the incident-response procedure, and a downloadable whitepaper.

Isolated per client. Every client has their own database schema and document repository instance.
AES-256 at rest. TLS 1.2 in transit. 2048-bit certificates with strong cipher suites across all connections.
13 data-center certifications. SOC 1/2/3, ISO 27001, PCI DSS Level 1, FedRAMP, HITRUST CSF, and more, held by AWS and not Workzoom-owned.
Canadian or US data residency. Selectable at onboarding. Data never leaves the chosen jurisdiction.

By the numbers

The security posture, documented.

13
data-center certifications inherited from AWS facilities
AES-256
encryption at rest. TLS 1.2 over 2048-bit certificates in transit.
100km
minimum distance between primary servers and off-site replicated backups
4 hr
response SLA for Critical (CVSS 9.0+) vulnerabilities

Hosting and certifications

AWS data centers. Canadian or US residency.

Workzoom is hosted on Amazon Web Services data centers in Canada and the United States. Clients choose data residency at onboarding. Workzoom uses AWS Global Accelerators and Edge Computing to route traffic to endpoints nearest each client.

SOC
SOC 1
Financial reporting controls
SOC 2
Trust services criteria
SOC 3
Public attestation
ISO
ISO 27001
Information security management
ISO 27017
Cloud-specific security
ISO 27018
Cloud personal-data protection
ISO 9001
Quality management
Government and frameworks
PCI DSS Level 1
Payment card data security
FedRAMP
US federal cloud authorization
HITRUST CSF
Healthcare information security
NIST
US cybersecurity framework
FIPS
US federal cryptographic standards
Privacy and cloud
CSA
Cloud Security Alliance

All certifications above are held at the data-center level by Amazon Web Services and apply to the infrastructure Workzoom runs on. Workzoom's own application-layer controls are documented on this page. AWS publishes the underlying audit reports under their Customer Compliance Program; Workzoom can share AWS SOC 1, SOC 2, SOC 3, and ISO 27701 reports under NDA on request via security@workzoom.com.

System architecture

Multi-tier Java, multi-threaded, isolated per client.

Workzoom is a proprietary platform written in Java on Tomcat web servers running on hardened Linux. Persistent data lives in MySQL. Documents and media live in MongoDB.

Every client has their own database schema and their own document repository instance, isolated from every other client.

Per-client isolation
Application software, web resources, meta-data, and common content are held outside the per-client databases. Every byte of client-specific data sits inside an isolated instance. Backup, recovery, and access policies all attach at the per-client level.
Self-healing cluster
Intelligent clustering uses auto-scaling and self-healing across multiple AWS Availability Zones. No single data-center incident takes the application down. Refreshable memory and file caches maintain top performance under load.
Private Data Cloud
Clients requiring physical isolation subscribe to the Workzoom Private Data Cloud: a dedicated database instance with separate encryption keys and a VPN-gated private network. No other client data resides on the server.
Network edge
Traffic is routed to the AWS endpoint nearest the client via AWS Global Accelerator and Edge Computing. Minimal latency for clients in Canada, the United States, the Caribbean, and the United Kingdom, without compromising data residency.

Replication, backup, recovery

100 km minimum distance. 24-hour maximum data exposure.

Real-time replication. Client data replicates in real time across AWS Availability Zones, a minimum of 100 km apart, to mitigate environmental and infrastructure failures.

Daily encrypted backups, off-site. Backups run daily, stored off-site at least 100 km from the primary. The last 5 are retained on-site; more frequent backups are available per client.

Recovery posture. On failure, clients switch to the replication environment. Intelligent clustering across AZs means no downtime from a single-data-center incident.

Encryption, authentication, SSO

AES-256 at rest. TLS 1.2 in transit. Federated SSO via SAML 2.0.

Data at rest
All client data at rest is encrypted with AES-256. In the Private Data Cloud option, encryption keys are managed in a separate key management server with no shared key material across clients.
Data in transit
All data in transit is encrypted using 128-bit-plus TLS 1.2 over TCP/IP with a 2048-bit certificate and strong cipher suites. Servers refuse to acknowledge connections from browsers or operating systems that do not support TLS 1.2.
Password protection
Passwords are encrypted with the PBKDF2WithHmacSHA1 algorithm, combining salted hashing with key stretching. Protection against dictionary, rainbow-table, and brute-force attacks. Policy configurable per client.
Single sign-on
Federated authentication via SAML 2.0. Native integrations with Microsoft Entra ID (formerly Azure AD), OneLogin, and Okta. Any other SAML 2.0 identity provider integrates through the standard protocol. See the SSO configuration guide.

Access management and logging

Role-based. Field-level. Sarbanes-Oxley compliant logging.

Role-based access control, down to the field

Workzoom is primarily role-based. Because the platform is built around HR, every user has a pre-defined role and responsibilities built into their job and position definition. The same role definition drives security: a user's role defines exactly what data they can view, add, update, or remove. When an exception is required, security can be applied at the individual user or group level, down to a single field if necessary.

Workzoom controls four dimensions of access independently:

WhoCan log in, with start and end dates
SubjectsWhat they can access
TasksWhat they can perform
DataView, add, update, or remove

Activity logging compliant with Sarbanes-Oxley

All logins and session activities are logged. For every login, action, or change, the application records the user, the process, the timestamp, the IP address, the original value, and the new value. Logging procedures are compliant with Sarbanes-Oxley requirements.

Workzoom staff access to client data

Access to client data is restricted to individuals who support the client. Every Workzoom employee signs a non-disclosure agreement and a code of ethics and is subject to background and criminal record checks as part of the new-hire process.

All Workzoom servers are isolated on their own VPC. Access to Workzoom servers is available only to a very limited set of authorized personnel, only through a VPN tunnel with TLS 1.2 ciphers and SHA-256 key exchange, with AES-256 encryption of all data inside the tunnel. Administrator access to infrastructure uses rotating access tokens. All VPN connection data is logged, and alerts fire on failed authentication attempts. All client data is securely removed from the cloud and from internal computers at the end of every engagement.

Security framework

Minimal attack surface. Least privilege. SELinux-hardened.

Attack-surface minimization
Workzoom servers reside in Virtual Private Clouds with security groups that close every external TCP and UDP port beyond HTTPS. All communication between Workzoom services is limited to within the secure VPC.
Least privilege
Root access on Workzoom servers is disabled. Elevated user privileges are strictly limited. All sudo-level commands are logged and monitored using industry-standard tools.
Privilege separation
Privilege separation is enforced via server hardening with SELinux. Process isolation ensures users and applications can only operate in areas absolutely necessary. Backup tools, for example, are only granted read-only privileges to the relevant databases.
Vulnerability management
Vulnerability scanning, penetration testing, hardware/software/application firewalls, comprehensive monitoring, logging, auditing, event management, and virus, trojan, and malware protection.
Live walkthrough

See Workzoom in 30 minutes.

Real product, real questions, no slides. Starts at $4 per employee per month, CAD or USD, with $0 setup fees.

No commitment 30 minutes

Vulnerability response SLA

Documented response and resolution times by CVSS 3.1 severity.

Workzoom uses the Common Vulnerability Scoring System (CVSS) version 3.1 to rate potential vulnerabilities. The SLA below applies from the moment Workzoom becomes aware of a vulnerability in the Workzoom platform, or from the moment a third-party vendor confirms a fix for an upstream component.

CVSS Base Score Response Time Resolution Time
9.0+ (Critical) 4 hours or less 80% resolved within 1 business day
7.0–8.9 (High) 1 business day or less 80% resolved within 5 business days
4.0–6.9 (Medium) 5 business days or less 80% resolved within 25 business days
0.1–3.9 (Low) Next regular release cycle Bundled with the next scheduled release

Incident response

Seven-step procedure, 24/7 monitoring.

Advanced monitoring is in place at the hardware, database, and application level. Hardware is monitored for data integrity, resource consumption, and network failure. Real-time replication and application availability are monitored 24/7, with alerts routed immediately to technical personnel. The procedure below executes on every confirmed security or privacy incident.

  1. 01Immediate escalationSecurity and senior management are informed within minutes of detection.
  2. 02Critical Incident ReportA report is started and tracked through resolution.
  3. 03Scope and severityThe Information Security Team assesses how far and how serious the incident is.
  4. 04Client communicationAffected clients are emailed, scaled to the scope and severity.
  5. 05Containment and restorationImmediate action to contain, restore availability, and prevent recurrence.
  6. 06Post-incident reviewRoot-cause analysis and risk mitigation are documented and applied.
  7. 07Per-client recoveryIf data is lost, clients get individual recovery plans.

Client penetration tests

Clients can run their own pen tests. Here is the policy.

Clients may conduct penetration tests and vulnerability assessments against Workzoom, either internally or through a third-party security firm, with Workzoom's prior approval. The policy:

  • 14 days advance notice of any testing, with a detailed outline of testing procedures and schedule.
  • Signed NDA from all parties involved before testing begins.
  • Un-redacted results related to Workzoom technologies provided within 7 days of testing completion.
  • Workzoom reserves the right to restrict testing scope, timing, methodology, or supplier where necessary to protect other clients in the multi-tenant environment.

Submit a pen test request to security@workzoom.com with the testing window, scope, and the firm performing the assessment.

Maintenance and release cycle

Most maintenance runs in the background. ~5 minutes weekly.

Weekly maintenance: a server restart of approximately five minutes. Most maintenance runs in the background with no client-visible impact.

Releases: a new Workzoom release ships approximately every two months. The release is staged in the background and activated after the regular server restart. Quarterly updates run off-hours over a weekend with minimal downtime.

Major releases: upgrades to a new major release are planned events. Workzoom provides clients a window of opportunity that suits their business cycle (avoiding active payroll runs, for example). All clients must be on the current release or the immediately previous release.

Sandbox: clients on a secondary Sandbox environment can preview an upcoming release for their own testing before production cutover.

Patching: OS-level and third-party application vulnerabilities deemed high-risk are tested and applied within timeframes appropriate to the assessed risk. All updates are tested on internal development and sandbox servers before production deployment.

For your security review team

Workzoom Architecture & Security Whitepaper

8-page PDF. Full architecture, hosting, certifications, encryption, replication, security framework, access management, vulnerability response, incident procedure, maintenance cycle, and pen-test policy. Cleared for distribution to your IT and security review teams without further NDA.

Download the PDF

FAQ

Workzoom security: common questions.

Workzoom is hosted on AWS infrastructure, which holds SOC 1, SOC 2, and SOC 3 audit attestations. These certifications belong to AWS and apply to the hosting environment, not to Workzoom directly. AWS publishes the underlying SOC reports under its Customer Compliance Program. Workzoom can share the AWS SOC 2 report under NDA on request. The Workzoom application layer is built and operated against the same control families. Email security@workzoom.com with your due-diligence request.
Workzoom client data is hosted on Amazon Web Services data centers in Canada or the United States, selectable at onboarding. Clients in Canada can elect Canadian data residency. Clients in the United States can elect US data residency. Data does not leave the chosen jurisdiction. Backup replicas remain in the same jurisdiction as the primary, at least 100 km from the primary servers.
Every Workzoom client has its own database schema and its own document repository instance. Application software, web resources, meta-data, and common content sit outside the per-client databases and are shared. Client-specific data is isolated end to end. For clients that require physical isolation, Workzoom offers a Private Data Cloud subscription that provides a dedicated database instance with separate encryption keys held in a key management server.
Data at rest is encrypted with AES-256. Data in transit is encrypted with TLS 1.2 over 2048-bit certificates with strong cipher suites. Passwords are encrypted with the PBKDF2WithHmacSHA1 algorithm using salted hashing with key stretching. Workzoom servers refuse to acknowledge connection requests from browsers or operating systems that do not support TLS 1.2.
Yes. Workzoom supports federated authentication via SAML 2.0. Native integrations include Microsoft Entra ID (formerly Azure AD), OneLogin, and Okta. Any other SAML 2.0 identity provider integrates through the standard protocol.
Yes, with prior approval. The policy requires 14 days advance notice, a detailed outline of testing procedures and schedule, a signed NDA from all parties, and un-redacted results related to Workzoom technologies within 7 days of completion. Submit requests to security@workzoom.com. Workzoom reserves the right to restrict scope, timing, or methodology to protect other clients in the multi-tenant environment.
Workzoom uses CVSS 3.1 to score vulnerabilities and commits to documented response and resolution times. Critical (9.0+): 4 hours or less to respond, 80% resolved within 1 business day. High (7.0–8.9): 1 business day to respond, 80% resolved within 5 business days. Medium (4.0–6.9): 5 business days to respond, 80% resolved within 25 business days. Low (0.1–3.9): bundled with the next scheduled release.
Weekly maintenance is approximately a 5-minute server restart. Most maintenance runs in the background. New releases ship roughly every two months and are activated after the regular weekly restart. Major releases are scheduled events that avoid critical client business cycles (active payroll runs, fiscal close). In the event of a major incident, recovery time is normally 5 minutes to 8 hours and maximum data exposure is 24 hours.

Need more for your security review?

Workzoom can share the SOC 2 Type II report and bridge letter under NDA. We respond to security questionnaires from RFPs, healthcare procurement, and Indigenous government buyers.