Home / Trust & Security

What we commit to, in writing

You are handing an automated system access to your customers, your phone line and your business data. This page sets out exactly what we promise, what we will not do, and which documents you can ask for before signing anything.

Straight answer

You will not find borrowed logos or invented statistics on this site

Most AI agency sites open with client logos and a "70% cost reduction" headline. Ask where the number came from and the answer is usually a vendor blog post.

We are early. We would rather tell you that than decorate the page. Every figure we publish will be measured in a named client's own reporting system, over a stated period, with their written approval — and until then this space stays empty.

What we would have to fake

and did not
  • Client logos we have no right to display
  • Testimonials written by us and attributed to a stock photo
  • Industry averages presented as our results
  • "Trusted by 500+ businesses" with no way to check
  • Certification badges we have not been audited for

If a competitor shows you any of these, ask them for the underlying report. It is a fair question and it is the same one you should ask us.

Commercial commitments

Six promises, each of them contractual

A promise on a website is marketing. The right-hand column tells you which document it actually lives in, so you can hold us to it.

Fixed implementation price, agreed before we start

Scope and price are signed off before any build work begins. If discovery uncovers something that changes the scope, we re-quote and you decide — we do not invoice a surprise.

Written inStatement of Work

Success measures agreed before we build

We define the baseline and the target with you first. If the pilot does not reach them, we tell you plainly and we do not move you onto a managed contract to keep the revenue.

Written inStatement of Work — pilot criteria

No long lock-in

The managed fee runs on a rolling basis with a notice period agreed upfront. Annual commitments are optional and discounted — never a condition of working with us.

Written inMaster Services Agreement

Your data stays yours, and you can take it with you

You own your knowledge base, transcripts, logs and extracted data. On request we export them in a standard format; on termination we delete our copies within the agreed period and confirm it in writing.

Written inData Processing Agreement

Your content is not used to train shared models

Your data is used to serve your workspace only. We pass this obligation down to every model provider and subprocessor we use, and we will show you those terms.

Written inDPA + subprocessor terms

We tell you when AI is the wrong answer

If a process is too low-volume, too high-risk or too poorly defined to automate well, we say so on the consultation call. We would rather lose the sale than deploy something that damages your customer relationships.

Written inOur proposal, every time
Security & data handling

How your data is actually handled

The detail below is confirmed per deployment in your Data Processing Agreement. Values marked in amber are set with you during scoping.

Controls

What is standard, and what you choose.

AreaHow it worksSet by
Data residencyProcessing and storage region selected at deploymentYour choice
EncryptionIn transit and at rest across our platform and storageStandard
Access controlLeast-privilege access for our team, per client workspaceStandard
Audit loggingConversations, calls, document runs and workflow executions logged with inputs, outputs and the decision takenStandard
Log retentionHow long transcripts, recordings and logs are keptSet in the DPA
Call recordingOn or off per deployment, with the disclosure your jurisdiction requiresYour choice
Deletion on terminationOur copies deleted within the agreed window, confirmed in writingStandard
Incident notificationYou are notified of a security incident affecting your data within the window agreed in the DPASet in the DPA
Penetration testing & certificationWe tell you exactly what we have and have not been audited for, rather than displaying a badgeCurrent position on request

Subprocessors

Every category of third party that can touch your data. We name each provider in the subprocessor list supplied with the security pack, and you are notified before that list changes.

CategoryPurposeNamed provider
Model providerLanguage understanding and generationIn the subprocessor list
SpeechSpeech-to-text and text-to-speech for voice agentsIn the subprocessor list
TelephonyCall routing and deliveryIn the subprocessor list
Cloud hostingApplication and data storageIn the subprocessor list
MessagingWhatsApp, SMS and social channel deliveryIn the subprocessor list
AI safeguards

The controls that stop an AI system embarrassing you

These are the failure modes that actually happen in production. Each one has a control, and each control is configured with you before go-live.

It invents an answer

Control: responses are grounded in the sources you connect. Anything outside them is escalated, not guessed, and each answer records which source it came from.

It handles something it should not

Control: explicit escalation triggers — complaints, refunds, distress, clinical or legal questions, value thresholds, or simply the customer asking for a person.

Someone thinks it is a person

Control: voice agents identify themselves as automated at the start of every call. We do not build agents that impersonate a named human being.

It writes bad data into a real system

Control: field-level confidence scores plus your validation rules. Anything that fails goes to a human queue rather than into your finance or clinical system.

It publishes something off-brand

Control: approval gates. Marketing output can require human sign-off before publishing, and negative reviews are always held for a person.

It quietly degrades over time

Control: the managed fee exists for this. We review escalation rates and failure cases on a set cycle and report what changed.

Limits

What we will not build

A short list, and we would rather you read it before the call than after the contract.

  • Voice or chat agents that pretend to be a specific named human
  • Untargeted cold outreach that ignores consent, opt-outs or quiet hours
  • Scraping that requires bypassing logins, paywalls or access controls
  • Unsupervised AI giving clinical, legal or financial advice to your customers
  • Automated decisions about a person with no route to a human review
  • Fake reviews, fake engagement or content designed to mislead

When we say don't automate it

honest cases
! Volume too lowmanual is cheaper
! Process undefinedfix it first
! Every case is an exceptionnothing to automate
! Source data is unreliablegarbage in
! The risk of being wrong is severekeep a human
Due diligence

Documents you can request

Ask before the first call if it helps your procurement or compliance team move faster. We do not gate these behind a sales process.

Data Processing AgreementRoles, purposes, residency, retention, deletion and subprocessor obligations
On request
Security packArchitecture, access control, encryption, logging, incident response and current certification status
On request
Named subprocessor listEvery third party that can process your data, with their role and location
On request
Master Services AgreementTerm, notice, liability, SLA and exit provisions
On request
Reference callOnce we have a live client who has agreed to take reference calls, we will offer one. Today we cannot, and we will not pretend otherwise.
Not yet available
Company

Where we are and how to reach us

Our full registration details go into the contract and are supplied on request during procurement. Everything you need to start a conversation is here.

Trading nameWorkGenesis
OfficeOne Liberty Plaza, 165 Broadway, 23rd Floor, New York, NY 10006, USA
Telephone+1 (646) 780-0928
Fax+1 (646) 780-0365
General & data protection contactinfo@workgenesis.ai
Security disclosuresinfo@workgenesis.ai

Report a vulnerability

we will not sue you

If you find a security issue in anything we run, tell us at info@workgenesis.ai.

1 We acknowledgewithin 2 business days
2 We assess and keep you updateduntil resolved
3 We credit youif you want it

Good-faith research reported this way will not be met with legal action.

FAQ

The questions procurement asks

Because we structure the engagement so the risk is small and staged. One workflow, a fixed implementation price, success measures agreed in writing, and a pilot you can walk away from. You are not signing a three-year platform contract on the strength of a logo wall.

You get an export of your knowledge base, transcripts, logs and extracted data in a standard format. We then delete our copies within the window set in the DPA and confirm the deletion in writing.

We will state our exact current position in the security pack rather than display a badge on a marketing page. Ask us directly and you will get a straight answer, including what we are not certified for.

Only the engineers assigned to your deployment, on a least-privilege basis, and only for building, supporting and reviewing your system. Access is logged. The named subprocessor list covers every third party that can process your data.

Every interaction is logged, so we can show you exactly what happened and why. Liability, indemnities and the incident process are set out in the Master Services Agreement — read them before signing, and bring your legal team to the scoping call if the deployment is sensitive.

Ask us the hard questions first

Request the DPA and security pack before you book anything. If the answers do not work for you, you have lost an email rather than a quarter.

Book a Free Consultation