Skip to content
New: Worksynk ships its own MCP server. Connect Claude in minutes →
[ Platform ]

Security and governance built for a client review

An encrypted credential vault AI can never read, IP allowlisting, a workspace activity log and project-level roles: the controls enterprise clients ask about before feature questions.

  • Vault contents never reachable by AI
  • IP and CIDR allowlisting
  • A searchable audit trail
Vault & accessWorkspace · Northwind

Credential vault

Production database••••••••
Stripe API keysk_live_••••
DNS registrar••••••••
Encrypted at restOne-time codeIP allowlist on

Access log

  • Priya A.Viewed Stripe API key09:42
  • Marcus F.Verified one-time code09:41
  • AI assistantBlocked: vault is off-limits09:30
/ AI or integration access to vault contents
0
/ credential view logged on the credential
Every
/ ranges supported in the IP allowlist
CIDR
[ How it works ]

Four layers, each narrowing the last

Roles decide what someone sees; network, vault and audit controls decide how, and leave a record.

  1. 01

    Roles decide visibility

    A workspace role plus a role per project decides whether someone sees a project at all, and that also limits reports, search and connected AI tools.

  2. 02

    Restrict the network

    IP Whitelist limits workspace access to the addresses and CIDR ranges you nominate, such as an office or a VPN egress.

  3. 03

    Keep secrets in the vault

    Client credentials live encrypted against their project, with a one-time code available as a second check before anyone views one.

  4. 04

    Audit what happened

    The Activity Log records logins, role and membership changes, settings and module changes, and integration changes.

[ Features ]

The controls a security questionnaire asks for

Each one is a module you switch on, and switching one off never deletes its data.

  • 01

    Credential Vault

    Encrypted at rest, decrypted only when someone with access views it, and never reachable by AI assistants or integrations.

  • 02

    Logged credential views

    Every view recorded on the credential itself: who opened what, and when.

  • 03

    IP Whitelist

    Workspace access limited to nominated addresses and CIDR ranges.

  • 04

    Activity Log

    A searchable, filterable record of consequential actions across the workspace.

  • 05

    Project-level roles

    Owner, manager, account manager, member and viewer per project, or your own roles.

  • 06

    Custom SMTP

    Workspace email sent through your own server, with credentials stored encrypted.

[ Capabilities ]

Governance detail

Including the restrictions that cannot be configured away.

AI-proof vaultCredential Vault
Vault contents are never reachable by connected AI assistants or third-party integrations, whatever access they hold.
One-time code to viewCredential Vault
Viewing a credential can require a code sent to you, so a borrowed session is not enough to read secrets.
Access follows the projectCredential Vault
Vault access follows project access, so removing someone from a project removes their vault access too.
Ranges, not just addressesIP Whitelist
Allow CIDR ranges for dynamic connections, or a VPN's stable egress for travelling teams.
Admin audit trailActivity Log
Owners and admins filter by action and by person; entries show the actor, what changed and when.
Two layers of rolesWorkspaces and people
Workspace owners and admins see every project; everyone else sees only projects they are a member of.
Timer proofTimer Security
Billed hours can require location or a known network when a timer starts.
[ Modules ]

The modules behind this page.

Worksynk ships as modules a workspace owner switches on under Settings → Modules. Most are off by default even when your plan covers them; pricing shows what each plan includes.

[ Questions ]

Common questions

Can a connected AI assistant read our client credentials?

No. Vault contents are deliberately never reachable by connected AI assistants or third-party integrations, whatever access they have been granted, and that restriction cannot be configured away.

Will IP whitelisting lock us out?

It can if you forget yourself. Add your current address, or your connection's range, before enabling it. For remote teams, allow a VPN's stable egress rather than individual addresses.

What does the Activity Log record?

Logins, membership and role changes, settings updates, module changes, integration and OAuth application changes, and other administrative actions. For who moved a task, the task's own history is the better place.

Where is the full list of controls?

The Security page lists every control with the module it lives in, and we will answer the detail behind any of them for a formal review.

Governed AI agents meant we could finally say yes to automation without losing the audit trail our compliance team needs.
Sam Whitfield / Director of PMO, Alderly Partners

/ Get started

Stop finding out about risk in the retro.

Score every project, catch scope creep while it is still cheap, and give clients a seat at the table, without another status meeting.

Free, full platform
90 days
Nothing up front
No card
Guided walkthrough
20 min