Security and trust

Werk24 protects your intellectual property with multi -layer protective measures in infrastructure, encryption, access control, monitoring and emergency recovery - designed for data residence in the EU / US.

Last checked: 05 June 2025

At a glance

Choose data residence in EU or USA

your choice:

  • EU: Frankfurt (eu-central-1); georedundant backup in Stockholm (eu-north-1).
  • USA: N. Virginia (us-east-1); georedundant backup in N. California (us-west-1).

Strong encryption

At rest with KMS (client -specific key);When transmission via TLS   1.2+ (TLS   1.3 preferred).

End-to-end encryption with volatile keys available.

Least privilege access

Strict IAM, service -specific roles, MFA/YUBIKEY and a logged administrator access.

Continuous monitoring

Cloudwatch, Guardduty, centralized unchangeable logs and anomaly alerts.

Backups & emergency recovery

Daily backups, PITR databases, RPO: 24 h, RTO: 4 h;Full restoration after complete failure tested.

Safe SDLC

IAC with terraform, protected CI/CD, weekly patches, ECR/dependency scans.

Security FAQ

Where is my data stored and processed?

Werk24 offers EU and US endpoints .

  • EU: frankfurt (EU-Central-1) with Georedundant backups in Stockholm (EU-north-1)
  • USA: N.Virginia (US-Eeatt-1) with GeoRedundant backups in N. California (US-West-1) .

The processing takes place in the region of the endpoints ;We do not replicate content across region.

Can EU customers use the US endpoint?

Yes. You can route individual or all workloads on our US endpoint. These inquiries are processed and saved in the USA.

There is no automatic replication between the EU and the USA;The data residence is determined by the end point you have chosen.

Which personal data do you process?

Werk24 processes as few personal data as possible. If the title blocks follow a standard format, we blacken the release area very early in the processing chain.

How are data encrypted?

in the idle state: AWS KMS with a CMK per client (SSE-KMS for connected customers; test data via SSE-S3). Key is rotated annually.

When transmission: tls   1.2+ (TLS   1.3 preferred) via ACM-managed certificates;MTLs for particularly sensitive internal services. Enterprise tariffs support end-to-end encryption with volatile keys.

Who has access to production systems?

The access-privilege principle follows: service-specific IAM rolls, separate accounts and MFA/Yubikey for administrators. Root access is severely restricted and requires approval by the CEO;Access data and keys are kept in the bank locking compartment.

How is the network protected?

segmented VPCs with public sub -networks for frontends and purely private subnettes for worker/inference. Security Groups limit service ports;Use sensitive services VPC endpoints (no run through the public internet). Public APIs are behind API Gateway/Alb with Waf.

What logging and monitoring do you use?

centralized logs (Cloudwatch, Cloudtrail) are unchangeable and versioned in S3 at least 12 months. Sentry delivers telemetry at the application level. Guardduty and Cloudwatch Alerts enable real-time anomali detection and standby alert.

How do you deal with weaknesses and patches?

weekly patch cycles (host amis, basic images, python dependencies);Ci forced the description of the desk/snyk/trunk tests;AWS ECR scans images at the push. High -critical topics are triached within 24 hours and remedied within 72 hours (exceptions are documented).

What does your backup and disaster recovery strategy look like?

daily backups with point-in-time recovery for critical databases;Backups are located in Frankfurt/Stockholm (EU) or the corresponding US regions. rpo 24 h , rto 4 h ;Complete restoration of the environment is practiced and is currently verified after a total failure in ~ 12 h.

Are single mandants or region-insulated deployments possible?

Yes. For customers with strict residence or insulation requirements, we provide a dedicated environment in the desired region-with separate KMS keys and client-specific iam boundaries.

Where can I see the complete security concept?

We provide our detailed "configuration & security concept" (versioned) on request- including architectural diagrams, process descriptions and test results for emergency recovery.

Register or ask for an individual assessment

Write to security@werk24.io . We are happy to answer your supplier questionnaire or agree a security review.