Skip to content
Security

Controls you can put in front of a security review

Client work means holding other people’s credentials, contracts, and roadmaps. Here is exactly what protects them, and what a connected AI assistant is allowed to touch.

Vault contents are never reachable by AI or integrations

Whatever access a connected assistant or third-party integration has been granted, stored credentials are out of reach. That restriction cannot be configured away.

How access is decided

Four layers combine to answer what any one person — or any one connection — can see. Each narrows the last; none of them widen it.

  1. 01

    Workspace role

    Sets the floor. Owners and admins can reach the whole workspace; everyone else starts narrower.

  2. 02

    Project role

    Narrows it per engagement, so someone on one client's project cannot see another's.

  3. 03

    Module state

    A disabled module hides its interface and blocks its endpoints — an access boundary, not a menu change.

  4. 04

    Client access level

    External people get a portal seat, a status link, or external-member access. Never an internal seat.

Controls

19 controls, and what each one actually does

Identity and access

Who gets in, and what they can reach once they are in.

Passkeys
WebAuthn sign-in with a fingerprint, Face ID, or a hardware key — nothing phishable to hand over.
Two-factor authentication
TOTP with recovery codes, or a code by email. The secret and the codes are encrypted at rest and never returned by the API.
Login history
Sign-ins are recorded, so an unfamiliar session is something you can actually find.
Workspace and project rolesWorkspaces
Two role layers that combine: a workspace role sets the floor, a project role narrows it per engagement.
IP allowlistIP Whitelist
Restrict workspace access to known addresses, so a leaked credential is not enough on its own.
Client access levelsClient portal
External people get a portal seat, a status link, or external-member access — never an internal seat.

Data protection

How secrets and files are stored and handed back.

Credential VaultVault
AES-256-GCM, encrypted at rest, decrypted only when someone with project access views it. Viewing can require a one-time code, so a borrowed session is not enough.
Vault access logVault
Every view is recorded — who opened which credential and when — and the log sits on the credential itself.
Upload handling
Attachments are allow-listed by type, double-extension filenames are rejected, and downloads are forced as attachments rather than rendered.
Timer SecurityTimer Security
Timers can require shared location or a recognised network before they start, for hours that have to withstand scrutiny.

Auditability

Answering “who did that, and when” after the fact.

Activity logActivity Log
A workspace-wide trail of who did what, and when.
MCP call recordsMCP Server
Every tool call an AI host makes is recorded, so there is a trail of what an assistant did.
Workspace access reviewMCP Server
Owners and admins see every AI connection and member API key reaching the workspace, and can revoke any of them immediately.

Integrations and AI

What connected systems are allowed to do on your behalf.

Connections act as a personMCP Server
An AI connection runs as whoever authorised it and can never see or do more than they can.
Read-only by defaultMCP Server
Write access is opt-in and executes immediately over MCP with no confirmation prompt — so grant it only where an assistant genuinely needs it.
Signed webhooksWebhooks
Outbound events are signed so the receiving system can verify the delivery came from your workspace.

Application hardening

Controls in the application layer itself.

Rich-text sanitisation
Descriptions and comments are sanitised server-side on write against an allow-list, and sanitised again in the browser before they render.
Response headers
X-Content-Type-Options, X-Frame-Options: DENY, and a strict Referrer-Policy on every response, plus HSTS over TLS.
Module gating
Disabling a module hides its interface and blocks its endpoints — it is an access boundary, not just a menu change.

Found something?

Report a suspected vulnerability to security@worksynk.test. Tell us what you found and how to reproduce it, and we’ll confirm receipt within one business day.

Running a formal review? Ask us for the detail behind any control on this page — we’d rather answer a hard question than have you guess.

Get started

Stop finding out about risk in the retro

Score every project, catch scope creep while it is still cheap, and give clients a seat at the table — without another status meeting.

90 days
Free, full platform
No card
Nothing to enter up front
20 min
Guided walkthrough on request