Security
Last updated: 13 May 2026
WorkGateIQ is built around a core principle: every safety decision must be trustworthy, traceable, and tamper-evident.
WorkGateIQ is hosted on managed cloud infrastructure with automatic security patching, encrypted data storage, and redundant backups. All data is encrypted at rest (AES-256) and in transit (TLS 1.2 minimum, TLS 1.3 preferred). Infrastructure is located within the United Kingdom and European Economic Area.
This is the most critical security feature of WorkGateIQ. Every Safety Gate decision — PASS, REFINE, or FAIL — is recorded with:
- A precise timestamp (UTC)
- The identity of the responsible person who authorised or reviewed the gate
- The full set of inputs that produced the decision
- The decision outcome and confidence scoring
- A version record — no decision can be silently altered after it is recorded
This immutable record means that in the event of a workplace incident, investigation, or HSE inspection, your organisation has a complete, honest, and unaltered account of every pre-work verification.
- Role-based access: Admin, Supervisor, and Standard User roles with appropriate permissions
- Authentication: Secure login with session management and automatic timeout
- Principle of least privilege: Users can only access and modify data within their assigned scope
- Audit logging: All system actions — including logins, record creation, edits, and decision outputs — are logged with timestamps and user identity
Safety Gate records are write-once by design. Once a gate decision is recorded, it cannot be deleted or silently modified. Corrections require a new gate record, ensuring the full decision history remains visible and honest. This design mirrors best practice in Permit to Work documentation under UK HSE guidance.
WorkGateIQ Pilot v1.0 does not yet hold formal third-party security certifications. We are transparent about this. We believe transparency about our current posture is more trustworthy than overclaiming certification we have not yet earned. Pilot partners receive full visibility of our security documentation on request.
We are working toward formal certification as the product matures.
If you discover a security vulnerability in WorkGateIQ, please report it responsibly to us before public disclosure. We commit to acknowledging your report within 48 hours and resolving confirmed vulnerabilities promptly.
support@edentouchcolab.com — Subject: SECURITY DISCLOSURE
In the event of a data breach affecting your organisation's data, we will notify affected organisations within 72 hours of becoming aware of the incident — in line with our obligations under UK GDPR Article 33. We will provide a clear account of what occurred, what data was affected, and the steps taken to contain and remediate the incident.
Security contact: support@edentouchcolab.com — Subject: SECURITY DISCLOSURE
Company: EdenTouch CoLab Ltd · Company No. 16472666 · ICO Reg: ZC047648