Security

SOC 2 Type II certification
SOC 2 (TYPE II)
NIST compliance badge
NIST
GDPR compliance badge
GDPR

Stepwork serves business customers of all sizes, from startups to global multinationals, in regulated industries. Enterprise-grade Zero Trust security is built into every layer of the stack and throughout the development lifecycle.

Security hero illustrationSecurity hero illustration
Security
Security hero illustration

Security you can trust every step of the way

We build security into everything we do because your trust is paramount. Every product, process, and system is designed with the protection of your data at its core.

Get a Demo

Security Features

Security features illustration
Local data storage
Locally stored

All your data stays on your own systems - either on your local machines or in your own cloud accounts. Nothing goes to third parties.

AWS Bedrock integration
AWS bedrock

AWS Bedrock provides secure API access to pre-trained AI models through your AWS account - no model training or data retention.

Docker containers
Hardened containers

We use hardened Docker containers to execute StepWork automations locally. By enforcing non-root execution and limiting communication to local apps via a minimal Flask server, we significantly reduce the attack surface.

Service accounts
Service accounts supported

Stepwork supports using service accounts to take actions on teams behalf. We mimic your existing security policies to reduce any unnecessary vulnerabilities

Audit logging
Every action logged

Every step is logged to ensure transparency and a papertrail. You can use these materials for audit purposes since everything is timestamped as well.

Hallucination prevention
Safety nets for hallucinations

Since we build the flows we’ve built in many mechanisms to account for potential hallucination risks to ensure the least risk possible for running workflows.

Self-hosted clusters
Hosting in your own cloud
(coming soon)

You have the ability to run flows in your own clusters to support multiple teams running flows through Stepwork.

The EU General Data 
Protection Regulation

Stepwork fully complies with privacy and AI laws and regulations including the European Union General Data Protection Regulation (GDPR) and AI Act, as well as with other national and U.S. state laws such as the California Consumer Privacy Act (CCPA).

GDPR compliance illustration
Data minimization - Only the minimum data required for Stepwork services is used.
Purpose limitation - Data access and use is limited to workflow automation only.
Integrity and confidentiality - Data is encrypted while access is strictly limited.
Storage limitation - Data is not retained beyond what is required for services or by law.
Accountability - Stepwork provides strong customer guarantees in all of its agreements.