InWork GlobalIntegrity. Urgency. Ownership.

Information Security Policy

Security by design, enforced at every layer.

No InWork Global system goes to production without a security review. We operate under SOC2-aligned practices, with ISO 27001 practices aligned and an ongoing formal program — MFA everywhere, AES-256 at rest, TLS 1.3 in transit, OWASP Top 10 addressed in development, and least-privilege access throughout.

SOC2-aligned practicesISO 27001 — practices alignedAES-256 / TLS 1.3OWASP Top 10
Information security policy and architecture

Security by design

Ten principles, applied without exception.

InWork's security policy is not a document that lives in a drawer — it is a set of architectural rules enforced on every engagement. No system goes to production without a security review, all authentication uses MFA, and least-privilege access is the default at every layer.

We operate under SOC2-aligned practices. On ISO 27001, our practices are aligned and we maintain an ongoing formal program. We state both positions plainly rather than overclaiming a certification we do not hold.

Security-by-design principles

The non-negotiables on every build.

No system goes to production without a security review
All authentication uses MFA
All data at rest is encrypted (AES-256)
All data in transit is encrypted (TLS 1.3+)
No secrets in source code
Least-privilege access at all layers
Production deployments in isolated VPCs with security groups
All code goes through peer review before merge
All third-party dependencies scanned for known vulnerabilities
All production access logged and monitored

Program controls

How the policy is operationalized.

Security by design extends beyond code into vendors, people, and incident response.

Vendor management

Third-party vendors with access to client data must provide evidence of their own security certifications (SOC2, ISO 27001), sign a Data Processing Agreement, agree to InWork's vendor security standards, and notify InWork within 24 hours of a security incident affecting client data.

Employee security

NDA and IP assignment agreement signed at hire, security awareness training at hire and annually, device encryption required for all laptops accessing production, and MFA on all corporate accounts.

Development security

OWASP Top 10 addressed in all code reviews, dependency scanning (npm audit, Snyk), no secrets in code, separated dev/staging/production environments, and production access restricted to senior engineers.

Encryption & access

AES-256 for data at rest, TLS 1.3 for data in transit, encrypted backups, key management via AWS KMS or Azure Key Vault, MFA, RBAC, least privilege, and quarterly access review.

Incident response

What happens when something goes wrong.

A defined, time-bound procedure — not improvisation under pressure.

1

Detection: automated monitoring plus employee reporting

2

Classification: severity 1–3 (1 = business-critical data exposure)

3

Containment: immediate isolation of affected systems

4

Notification: client notification within 4 hours of Severity 1 identification

5

Resolution: root cause analysis and remediation plan

6

Post-incident: report to client within 72 hours of resolution

SOC2-aligned

ISO 27001 — practices aligned, ongoing formal program

InWork operates under SOC2-aligned security practices, with ISO 27001 practices aligned and an ongoing formal program. We implement the controls these frameworks require and state our certification status transparently.

Compliance by design

Ship on infrastructure built to a security standard.

Every InWork engagement includes a security architecture review. Tell us about your data and your threat model.

Integrity. Urgency. Ownership.

Schedule a security reviewRequest a proposal

40+ US businesses served · 65+ engineers · Zero long-term lock-in

Book a Strategy Call