Every security review we go through opens with the same three questions. Rather than answer them one procurement form at a time, here are the answers in public.
Where the data is
All Workerflow data is stored and processed on EU infrastructure, in the Belgium region. That covers workflow definitions, execution logs, conversation history and the contents of your data stores. There are no transfers outside the EEA in the normal operation of the platform.
What happens to it
Your content is not used to train AI models. Not by us, and not by the model providers we route requests to. We only work with providers that contractually commit to zero data retention on the endpoints we use, and we verify that commitment per model before we make it available in the platform.
That last part is worth spelling out. "The provider offers a no-retention option" is not the same as "the model you selected runs on it". We check at the level of the individual model endpoint, and a model that cannot meet the bar does not get added.
How you verify it
Transparency is the reason the platform exists, so it applies to us too:
- Every run produces a full execution log. Inputs, model responses, condition results, tool calls, state changes and outcomes, timestamped.
- The model behind each step is recorded. You always know what processed a given piece of data.
- Logs can be exported. Your compliance team can review them outside the platform.
Deletion
You can delete workflows, sessions, data stores and records at any time. Account-level deletion requests are processed within 30 days. Details on retention and your rights as a data subject are in our privacy policy.
If your security review needs something more specific than this, write to us and we will answer it directly rather than pointing you at a document.
