Security & Trust
IQWorks is a data protection platform — security is not a feature, it is the product. Review our controls, certifications, policies, and sub-processors below.
Compliance & Certifications
Our compliance posture across global privacy and security frameworks.
SOC 2 Type II
In ProgressAudit underway covering security, availability, and confidentiality criteria.
GDPR
CompliantFull compliance with EU General Data Protection Regulation. DPA available on request.
DPDP Act 2023
CompliantAligned with India's Digital Personal Data Protection Act 2023.
CCPA
CompliantCalifornia Consumer Privacy Act requirements for data subject rights.
ISO 27001
PlannedISO 27001 certification on our roadmap as we mature our ISMS.
Security Controls
Defense-in-depth controls across infrastructure, product, and organization.
Sub-processors
Third-party vendors that may process customer data on our behalf. We notify customers 30 days before adding new sub-processors.
| Vendor | Purpose | Data Location | Certifications | Trust Page |
|---|---|---|---|---|
| Cloud infrastructure & data storage | India (ap-south-1), configurable | SOC 2ISO 27001 | View | |
| Database, realtime, and auth primitives | Hosted on AWS (same region) | SOC 2 | View | |
| Frontend hosting and edge network | Global CDN | SOC 2 | View | |
| Authentication and identity management | India / EU configurable | SOC 2ISO 27001 | View | |
| CDN, DDoS protection, WAF | Global | SOC 2ISO 27001 | View | |
| AI model inference (opt-in features only) | US (data not used for training) | SOC 2 | View | |
| AI model inference (opt-in features only) | US (data not used for training) | SOC 2 | View | |
| Product analytics (anonymized) | EU (eu.posthog.com) | SOC 2 | View | |
| Transactional email delivery | US | SOC 2 | View |
Policies & Documents
Open documents are publicly available. Locked documents are shared under NDA — email us to request access.
Responsible Disclosure
Found a security vulnerability? We appreciate responsible disclosure.
- We acknowledge valid reports within 24 hours
- Critical vulnerabilities patched within 24 hours
- No legal action against good-faith researchers
- Credit given for valid disclosures (optional)
System Status
Real-time uptime, incident history, and maintenance windows for all services.
status.iqworks.aiSecurity FAQ
Common questions from enterprise security reviews
Have a question not covered here? Contact our security team