Security and governance built for a client review
An encrypted credential vault AI can never read, IP allowlisting, a workspace activity log and project-level roles: the controls enterprise clients ask about before feature questions.
- Vault contents never reachable by AI
- IP and CIDR allowlisting
- A searchable audit trail
Credential vault
Access log
- Priya A.Viewed Stripe API key09:42
- Marcus F.Verified one-time code09:41
- AI assistantBlocked: vault is off-limits09:30
- / AI or integration access to vault contents
- 0
- / credential view logged on the credential
- Every
- / ranges supported in the IP allowlist
- CIDR
Four layers, each narrowing the last
Roles decide what someone sees; network, vault and audit controls decide how, and leave a record.
- 01
Roles decide visibility
A workspace role plus a role per project decides whether someone sees a project at all, and that also limits reports, search and connected AI tools.
- 02
Restrict the network
IP Whitelist limits workspace access to the addresses and CIDR ranges you nominate, such as an office or a VPN egress.
- 03
Keep secrets in the vault
Client credentials live encrypted against their project, with a one-time code available as a second check before anyone views one.
- 04
Audit what happened
The Activity Log records logins, role and membership changes, settings and module changes, and integration changes.
The controls a security questionnaire asks for
Each one is a module you switch on, and switching one off never deletes its data.
- 01
Credential Vault
Encrypted at rest, decrypted only when someone with access views it, and never reachable by AI assistants or integrations.
- 02
Logged credential views
Every view recorded on the credential itself: who opened what, and when.
- 03
IP Whitelist
Workspace access limited to nominated addresses and CIDR ranges.
- 04
Activity Log
A searchable, filterable record of consequential actions across the workspace.
- 05
Project-level roles
Owner, manager, account manager, member and viewer per project, or your own roles.
- 06
Custom SMTP
Workspace email sent through your own server, with credentials stored encrypted.
Governance detail
Including the restrictions that cannot be configured away.
- AI-proof vaultCredential Vault
- Vault contents are never reachable by connected AI assistants or third-party integrations, whatever access they hold.
- One-time code to viewCredential Vault
- Viewing a credential can require a code sent to you, so a borrowed session is not enough to read secrets.
- Access follows the projectCredential Vault
- Vault access follows project access, so removing someone from a project removes their vault access too.
- Ranges, not just addressesIP Whitelist
- Allow CIDR ranges for dynamic connections, or a VPN's stable egress for travelling teams.
- Admin audit trailActivity Log
- Owners and admins filter by action and by person; entries show the actor, what changed and when.
- Two layers of rolesWorkspaces and people
- Workspace owners and admins see every project; everyone else sees only projects they are a member of.
- Timer proofTimer Security
- Billed hours can require location or a known network when a timer starts.
The modules behind this page.
Worksynk ships as modules a workspace owner switches on under Settings → Modules. Most are off by default even when your plan covers them; pricing shows what each plan includes.
- Security and administration01Credential VaultEncrypted storage for the secrets a project needs.Read the guide ↗ for Credential Vault (opens the docs)
- Security and administration02IP WhitelistRestrict workspace access to known addresses.Read the guide ↗ for IP Whitelist (opens the docs)
- Security and administration03Activity LogA workspace-wide audit trail of who did what, and when.Read the guide ↗ for Activity Log (opens the docs)
- Security and administration04Workspaces and peopleWorkspace roles, project roles, and how the two combine to decide what someone sees.Read the guide ↗ for Workspaces and people (opens the docs)
- Security and administration05Custom SMTPSend workspace email through your own mail server.Read the guide ↗ for Custom SMTP (opens the docs)
- Time, cost, and reporting06Timer SecurityRequire location or a known network when starting a timer.Read the guide ↗ for Timer Security (opens the docs)
Common questions
Can a connected AI assistant read our client credentials?
No. Vault contents are deliberately never reachable by connected AI assistants or third-party integrations, whatever access they have been granted, and that restriction cannot be configured away.
Will IP whitelisting lock us out?
It can if you forget yourself. Add your current address, or your connection's range, before enabling it. For remote teams, allow a VPN's stable egress rather than individual addresses.
What does the Activity Log record?
Logins, membership and role changes, settings updates, module changes, integration and OAuth application changes, and other administrative actions. For who moved a task, the task's own history is the better place.
Where is the full list of controls?
The Security page lists every control with the module it lives in, and we will answer the detail behind any of them for a formal review.
Governed AI agents meant we could finally say yes to automation without losing the audit trail our compliance team needs.
Where to go next.
- PlatformMeetings & KnowledgeSchedule Zoom, Google Meet and Teams calls against a project, keep notes and files beside the work they concern, and automate the repetitive parts of delivery.Explore
- PlatformWork items & sprintsTasks carry status, type, priority, assignee, and dates. Sprints pace the work, milestones give it a dated outcome, and timers make the hours honest enough to bill from.Explore
- SolutionsPMO & opsOne delivery model and one set of definitions across every team, without slowing anyone down — modules, statuses, and workflows each workspace can shape to fit how it actually works.Explore
/ Get started
Stop finding out about risk in the retro.
Score every project, catch scope creep while it is still cheap, and give clients a seat at the table, without another status meeting.
- Free, full platform
- 90 days
- Nothing up front
- No card
- Guided walkthrough
- 20 min