Information Security Policy
Security by design, enforced at every layer.
No InWork Global system goes to production without a security review. We operate under SOC2-aligned practices, with ISO 27001 practices aligned and an ongoing formal program — MFA everywhere, AES-256 at rest, TLS 1.3 in transit, OWASP Top 10 addressed in development, and least-privilege access throughout.

Security by design
Ten principles, applied without exception.
InWork's security policy is not a document that lives in a drawer — it is a set of architectural rules enforced on every engagement. No system goes to production without a security review, all authentication uses MFA, and least-privilege access is the default at every layer.
We operate under SOC2-aligned practices. On ISO 27001, our practices are aligned and we maintain an ongoing formal program. We state both positions plainly rather than overclaiming a certification we do not hold.
Security-by-design principles
The non-negotiables on every build.
Program controls
How the policy is operationalized.
Security by design extends beyond code into vendors, people, and incident response.
Vendor management
Third-party vendors with access to client data must provide evidence of their own security certifications (SOC2, ISO 27001), sign a Data Processing Agreement, agree to InWork's vendor security standards, and notify InWork within 24 hours of a security incident affecting client data.
Employee security
NDA and IP assignment agreement signed at hire, security awareness training at hire and annually, device encryption required for all laptops accessing production, and MFA on all corporate accounts.
Development security
OWASP Top 10 addressed in all code reviews, dependency scanning (npm audit, Snyk), no secrets in code, separated dev/staging/production environments, and production access restricted to senior engineers.
Encryption & access
AES-256 for data at rest, TLS 1.3 for data in transit, encrypted backups, key management via AWS KMS or Azure Key Vault, MFA, RBAC, least privilege, and quarterly access review.
Incident response
What happens when something goes wrong.
A defined, time-bound procedure — not improvisation under pressure.
Detection: automated monitoring plus employee reporting
Classification: severity 1–3 (1 = business-critical data exposure)
Containment: immediate isolation of affected systems
Notification: client notification within 4 hours of Severity 1 identification
Resolution: root cause analysis and remediation plan
Post-incident: report to client within 72 hours of resolution
SOC2-aligned
ISO 27001 — practices aligned, ongoing formal program
InWork operates under SOC2-aligned security practices, with ISO 27001 practices aligned and an ongoing formal program. We implement the controls these frameworks require and state our certification status transparently.
