Trust & Security

Last updated September 1, 2026. Back to Vorklee

1. Our commitment

Vorklee is built for multi-tenant business data. We enforce authentication on every protected route, org-scoped data access, mutation origin checks, and scrubbed observability.

Security-sensitive operations go through platform gateways (Save, AI, sharing, org access) so new apps inherit the same controls.

2. Responsible disclosure

If you believe you found a security vulnerability, email security@vorklee.com with steps to reproduce, impact, and your contact details.

Please do not publicly disclose issues until we confirm a fix or agree on a timeline. We aim to acknowledge reports within 3 business days.

3. Privacy and compliance

See our Privacy Policy for GDPR, CCPA/CPRA, and India DPDP coverage. Organization administrators manage DSAR export and erasure from VHome.

Subprocessors and data retention details are published on our Subprocessors page and internal compliance pack.

4. System status

A dedicated Vorklee status page is planned. Until then, check vendor status pages for infrastructure incidents that may affect the platform.

Trust & Security | Vorklee