Security: what WorkOS does and what's up to you
WorkOS works on top of tools your company already uses, such as Notion, Google or Microsoft. That's why security is split between three parties.
What WorkOS does
- Protect access to the app: temporary codes, signing in with Google, limits on repeated attempts and encrypted connections.
- Apply each person's permissions and keep each company's information separate.
- Encrypt the connection credentials to your tools and never store sign-in codes in plain text.
- Work only with AI providers that don't train on your data, and ask for your confirmation before Kairos changes anything.
- Limit what the AI can do from outside WorkOS: from Claude or ChatGPT it's not possible to send emails, publish or invite anyone.
- Protect its own support access: individual accounts with Google and a preview of your account that only allows viewing.
- Review the security of each new feature before releasing it.
What your tools do
- Notion stores your work content and has its own measures: encryption, version history and trash. What you can recover and for how long depends on your Notion plan.
- Google or Microsoft protect your email, your calendar and your Drive, including two-step verification on each account.
What's up to your company
- Turn on two-step verification for each person's email, in Google Workspace or Microsoft 365, and in Notion.
- Offboard whoever leaves the company: deactivate their user in Settings → Team, disconnect their accounts and remove their access to Notion and Drive.
- Decide which Notion databases and which Drive folder you connect, and who they're shared with.
- Assign roles carefully. Only people who need it should be Owner or Technical contact.
- Review Kairos's proposals before confirming them, especially if they involve emails from unknown senders.
- Let us know as soon as possible if you suspect unauthorized access. See “How to report a security issue”.