Worxley
Worxley
முதன்மைஅம்சங்கள்Explore core CRM capabilitiesஇணைப்புகள்Connect your favorite toolsWorxley AIAI built into workflowsMCPConnect with Claude & ChatGPT
பயன்பாட்டு நிகழ்வுகள்லீட் மேலாண்மைCapture and convert leadsவிற்பனை மேலாண்மைManage pipeline and revenueவாடிக்கையாளர் மேலாண்மைSupport and retain customers
தொழில்துறைகள்IT சேவைகள்For tech and IT agenciesடிஜிட்டல் மார்க்கெட்டிங்For creative and ad agenciesதொழில்முறை சேவைகள்For consulting and legalரியல் எஸ்டேட்For brokers and developersசுற்றுலாFor travel and hospitality
கற்றுக்கொள்CRM வழிகாட்டிகள்விரைவில்Step-by-step product tutorialsதொழில்துறை வழிகாட்டிகள்Tailored insights for your sector
கருவிகள்டெம்ப்ளேட்கள்விரைவில்Ready-to-use workflowsகருவிகள்விரைவில்Free utilities for your team
ஆதரவுஉதவி மையம்Get answers and contact support
தயாரிப்புபயன்பாட்டு நிகழ்வுகள்Discover how others use Worxleyமாற்றப் பட்டியல்See what's new and improvedவலைப்பதிவுRead our latest articles
பங்குதாரர்கள்பங்குதாரர் திட்டம்Join the Worxley partner network
விலை
உள்நுழைவுஇலவசத் தொடக்கம்
முதன்மைஅம்சங்கள்Explore core CRM capabilitiesஇணைப்புகள்Connect your favorite toolsWorxley AIAI built into workflowsMCPConnect with Claude & ChatGPT
பயன்பாட்டு நிகழ்வுகள்லீட் மேலாண்மைCapture and convert leadsவிற்பனை மேலாண்மைManage pipeline and revenueவாடிக்கையாளர் மேலாண்மைSupport and retain customers
தொழில்துறைகள்IT சேவைகள்For tech and IT agenciesடிஜிட்டல் மார்க்கெட்டிங்For creative and ad agenciesதொழில்முறை சேவைகள்For consulting and legalரியல் எஸ்டேட்For brokers and developersசுற்றுலாFor travel and hospitality
கற்றுக்கொள்CRM வழிகாட்டிகள்விரைவில்Step-by-step product tutorialsதொழில்துறை வழிகாட்டிகள்Tailored insights for your sector
கருவிகள்டெம்ப்ளேட்கள்விரைவில்Ready-to-use workflowsகருவிகள்விரைவில்Free utilities for your team
ஆதரவுஉதவி மையம்Get answers and contact support
தயாரிப்புபயன்பாட்டு நிகழ்வுகள்Discover how others use Worxleyமாற்றப் பட்டியல்See what's new and improvedவலைப்பதிவுRead our latest articles
பங்குதாரர்கள்பங்குதாரர் திட்டம்Join the Worxley partner network
விலை
உள்நுழைவுஇலவசத் தொடக்கம்

Security at Worxley

Last reviewed: June 1, 2026 Audited quarterly by independent security firms
AES-256-GCM at rest TLS 1.3 in transit Zero data selling 99.97% Uptime SLA
Contents
Our CommitmentInfrastructure SecurityEncryptionAccess ControlApplication SecurityOperational SecurityIncident ResponseVendor SecurityVulnerability Disclosure

Our Commitment

Worxley handles some of the most sensitive data a business holds — customer and lead records, communication history, deal and quotation details, and payment information. We take this responsibility seriously. Security is not a feature we added after the fact; it is built into every layer of the platform.

This page describes the technical and administrative measures we have implemented to protect your data. If you have specific security questions about a deployment, contact us at security@worxley.com.

Security principle: We operate on a zero-trust model — every access request is verified, every sensitive action is logged, and the principle of least privilege governs who can see what.

Infrastructure Security

Data Centre & Hosting

All Worxley infrastructure is hosted in India — specifically in the Mumbai (ap-south-1) region — on ISO 27001 and SOC 2 Type II certified data centre facilities. We do not host customer data outside India. Data is replicated across geographically separated availability zones within India for high availability and disaster recovery, without any cross-border transfer.

Network Security

Our production environment is isolated in a private Virtual Private Cloud (VPC). All public-facing components sit behind a managed Web Application Firewall (WAF) with continuous DDoS mitigation. Internal service-to-service communication occurs exclusively within private subnets. Inbound access to production servers is restricted to specific IP ranges via security groups; direct SSH access from the public internet is not permitted.

Availability SLA

We maintain a target uptime SLA of 99.97% for Worxley. Our infrastructure is designed with redundancy at every layer — compute, database, and storage. Automated health monitoring and alerting is active 24/7. We publish a real-time status page at status.worxley.com.

Backups & Retention

Customer data is backed up automatically every 24 hours with a minimum retention of 30 days. Backups are encrypted at rest using the same AES-256 standard as primary data. Backup restoration is tested quarterly.

Encryption

Worxley applies encryption at every layer where sensitive data is stored or transmitted:

LayerStandardScope
Data at restAES-256-GCMAll database storage, backups, and file assets
Sensitive fieldsAES-256-CBC (field-level)Payment details, customer PII, deal and quotation financial data
Data in transitTLS 1.3All API calls, web traffic, and internal service communication
Passwordsbcrypt (cost factor 12)User passwords — never stored in plaintext
Session tokensHMAC-SHA256 signed JWTsShort-lived tokens, rotated on each session

TLS 1.0 and 1.1 are disabled across all Worxley endpoints. We enforce HSTS with a minimum one-year max-age across all production domains. Certificates are issued by trusted public CAs and rotated automatically before expiry.

Access Control

Role-Based Access Control (RBAC)

Access to data within Worxley is governed by a granular RBAC system. Permissions are configured at the field level — meaning a support rep can be given access to customer tickets but not deal financials, or a sales manager can view their team's pipeline but not company-wide revenue reports. Every permission combination is explicitly granted; default access is deny.

Multi-Factor Authentication (MFA)

Multi-factor authentication is available for all Worxley accounts and is mandatory for administrator-level users. We support TOTP-based authenticator apps. Accounts with admin privileges that do not have MFA enabled are flagged and escalated.

Internal Access Controls

Our employees do not have standing access to customer production data. Customer data access by our personnel requires a time-limited, approvals-based access grant, is logged with justification, and is reviewed by our security team. Our engineers access production systems only through a bastion host with mandatory MFA.

Audit Logging

All login events, data access events, configuration changes, and administrative actions are logged with timestamps, user identity, IP address, and session ID. Logs are tamper-proof, retained for 12 months, and monitored for anomalies in real time.

Application Security

Secure Development Lifecycle (SDLC)

Security is integrated into our development process from the design stage. All new features undergo security design review before development begins. Code changes are reviewed by a second engineer before merging. Automated SAST (static analysis) and dependency vulnerability scanning run on every pull request.

Vulnerability Testing & Remediation SLAs

We conduct third-party penetration tests at least once per year, and after any major architectural change. Identified vulnerabilities are triaged by severity and remediated within defined SLAs:

SeverityRemediation Target SLA
Critical24 hours
High7 days
Medium30 days
Low / InformationalNext planned release

OWASP Protections

Our application is built with defences against the OWASP Top 10, including parameterised queries (SQL injection prevention), CSP headers and output encoding (XSS prevention), CSRF tokens on all state-changing requests, rate limiting on authentication endpoints, and secure cookie attributes (HttpOnly, Secure, SameSite=Strict).

Operational Security

Employee Security

All Worxley employees undergo background verification before joining. Every team member receives mandatory security awareness training at onboarding and annually thereafter. Employees handling customer data sign confidentiality agreements that survive their employment.

Device Security & MDM

All company-managed devices are enrolled in a Mobile Device Management (MDM) system. Full-disk encryption is mandatory on all endpoints. Screen lock policies, remote wipe capability, and automatic OS update enforcement are applied universally.

Secrets Management

API keys, database credentials, and secrets are stored in a centralized secrets management vault, never in source code or configuration files. Secrets are rotated on a scheduled basis and immediately upon any suspected compromise.

Incident Response & Breach Protocol

We maintain a documented incident response plan that is tested through tabletop exercises at least twice per year. In the event of a confirmed security incident:

  • Detection & containment: Automated monitoring systems alert the on-call team immediately. Affected systems are isolated to contain the incident.
  • Assessment: Forensic evaluation determines the scope, nature, and impact of the incident.
  • Customer notification: If a breach involves your Customer Data, we will notify you within 72 hours of breach confirmation.
  • Remediation & post-mortem: Root cause is remediated, systems restored, and a written post-mortem shared within 14 days.

To report a suspected security incident, email security@worxley.com immediately.

Vendor Security

We maintain a strict vetting process for third-party vendors and sub-processors. Vendors with access to customer data sign Data Processing Agreements requiring security standards equivalent to our own and 48-hour incident notification SLAs.

Vulnerability Disclosure

We welcome responsible disclosure from security researchers. If you have discovered a potential vulnerability, please email security@worxley.com with steps to reproduce. We acknowledge reports within 2 business days and do not pursue legal action against researchers acting in good faith.

Worxley
Worxley

AI-முதன்மை வாடிக்கையாளர் செயல்பாட்டு தளம் — விற்பனை, சந்தைப்படுத்தல், சேவை மற்றும் தானியங்கு செயல்முறையை ஒரே அமைப்பில் இணைக்கிறது.

இலவசத் தொடக்கம்
தயாரிப்பு
  • அனைத்து அம்சங்கள்
  • விலை திட்டங்கள்
  • பயன்பாட்டு நிகழ்வுகள்
  • வாடிக்கையாளர் செயல்பாடுகள் என்றால் என்ன?
ஒப்பிடுக
  • ஸ்பிரெட்ஷீட்கள்
  • Zoho CRM
  • HubSpot
  • Pipedrive
அம்சங்கள்
  • லீட் மேலாண்மை
  • விற்பனை மேலாண்மை
  • வாடிக்கையாளர் மேலாண்மை
  • இணைப்புகள்
  • Worxley AI
  • பங்குதாரர் நெட்வொர்க்
தீர்வுகள்
  • IT சேவைகள்
  • டிஜிட்டல் மார்க்கெட்டிங்
  • தொழில்முறை சேவைகள்
  • ரியல் எஸ்டேட்
  • சுற்றுலா
நிறுவனம்
  • நிறுவனப் பங்குதாரர்
  • வலைப்பதிவு
  • மாற்றப் பட்டியல்
  • அடிக்கடி கேட்கப்படும் கேள்விகள்
  • உதவி மையம்
  • எங்களை தொடர்பு கொள்ளுங்கள்
எங்களை தொடர்பு கொள்ளுங்கள்|பாதுகாப்பு|இணக்கம்|அணுகல்தன்மை|சேவை விதிமுறைகள்|தனியுரிமைக் கொள்கை|குக்கீ கொள்கை||நிலை
Acadyn Labs LLP
© 2026, Acadyn Labs LLP. அனைத்து உரிமைகளும் பாதுகாக்கப்பட்டவை.