It invents an answer
Control: responses are grounded in the sources you connect. Anything outside them is escalated, not guessed, and each answer records which source it came from.
Home / Trust & Security
You are handing an automated system access to your customers, your phone line and your business data. This page sets out exactly what we promise, what we will not do, and which documents you can ask for before signing anything.
Most AI agency sites open with client logos and a "70% cost reduction" headline. Ask where the number came from and the answer is usually a vendor blog post.
We are early. We would rather tell you that than decorate the page. Every figure we publish will be measured in a named client's own reporting system, over a stated period, with their written approval — and until then this space stays empty.
If a competitor shows you any of these, ask them for the underlying report. It is a fair question and it is the same one you should ask us.
A promise on a website is marketing. The right-hand column tells you which document it actually lives in, so you can hold us to it.
Scope and price are signed off before any build work begins. If discovery uncovers something that changes the scope, we re-quote and you decide — we do not invoice a surprise.
We define the baseline and the target with you first. If the pilot does not reach them, we tell you plainly and we do not move you onto a managed contract to keep the revenue.
The managed fee runs on a rolling basis with a notice period agreed upfront. Annual commitments are optional and discounted — never a condition of working with us.
You own your knowledge base, transcripts, logs and extracted data. On request we export them in a standard format; on termination we delete our copies within the agreed period and confirm it in writing.
Your data is used to serve your workspace only. We pass this obligation down to every model provider and subprocessor we use, and we will show you those terms.
If a process is too low-volume, too high-risk or too poorly defined to automate well, we say so on the consultation call. We would rather lose the sale than deploy something that damages your customer relationships.
The detail below is confirmed per deployment in your Data Processing Agreement. Values marked in amber are set with you during scoping.
What is standard, and what you choose.
| Area | How it works | Set by |
|---|---|---|
| Data residency | Processing and storage region selected at deployment | Your choice |
| Encryption | In transit and at rest across our platform and storage | Standard |
| Access control | Least-privilege access for our team, per client workspace | Standard |
| Audit logging | Conversations, calls, document runs and workflow executions logged with inputs, outputs and the decision taken | Standard |
| Log retention | How long transcripts, recordings and logs are kept | Set in the DPA |
| Call recording | On or off per deployment, with the disclosure your jurisdiction requires | Your choice |
| Deletion on termination | Our copies deleted within the agreed window, confirmed in writing | Standard |
| Incident notification | You are notified of a security incident affecting your data within the window agreed in the DPA | Set in the DPA |
| Penetration testing & certification | We tell you exactly what we have and have not been audited for, rather than displaying a badge | Current position on request |
Every category of third party that can touch your data. We name each provider in the subprocessor list supplied with the security pack, and you are notified before that list changes.
| Category | Purpose | Named provider |
|---|---|---|
| Model provider | Language understanding and generation | In the subprocessor list |
| Speech | Speech-to-text and text-to-speech for voice agents | In the subprocessor list |
| Telephony | Call routing and delivery | In the subprocessor list |
| Cloud hosting | Application and data storage | In the subprocessor list |
| Messaging | WhatsApp, SMS and social channel delivery | In the subprocessor list |
These are the failure modes that actually happen in production. Each one has a control, and each control is configured with you before go-live.
Control: responses are grounded in the sources you connect. Anything outside them is escalated, not guessed, and each answer records which source it came from.
Control: explicit escalation triggers — complaints, refunds, distress, clinical or legal questions, value thresholds, or simply the customer asking for a person.
Control: voice agents identify themselves as automated at the start of every call. We do not build agents that impersonate a named human being.
Control: field-level confidence scores plus your validation rules. Anything that fails goes to a human queue rather than into your finance or clinical system.
Control: approval gates. Marketing output can require human sign-off before publishing, and negative reviews are always held for a person.
Control: the managed fee exists for this. We review escalation rates and failure cases on a set cycle and report what changed.
A short list, and we would rather you read it before the call than after the contract.
Ask before the first call if it helps your procurement or compliance team move faster. We do not gate these behind a sales process.
Our full registration details go into the contract and are supplied on request during procurement. Everything you need to start a conversation is here.
| Trading name | WorkGenesis |
| Office | One Liberty Plaza, 165 Broadway, 23rd Floor, New York, NY 10006, USA |
| Telephone | +1 (646) 780-0928 |
| Fax | +1 (646) 780-0365 |
| General & data protection contact | info@workgenesis.ai |
| Security disclosures | info@workgenesis.ai |
If you find a security issue in anything we run, tell us at info@workgenesis.ai.
Good-faith research reported this way will not be met with legal action.
Because we structure the engagement so the risk is small and staged. One workflow, a fixed implementation price, success measures agreed in writing, and a pilot you can walk away from. You are not signing a three-year platform contract on the strength of a logo wall.
You get an export of your knowledge base, transcripts, logs and extracted data in a standard format. We then delete our copies within the window set in the DPA and confirm the deletion in writing.
We will state our exact current position in the security pack rather than display a badge on a marketing page. Ask us directly and you will get a straight answer, including what we are not certified for.
Only the engineers assigned to your deployment, on a least-privilege basis, and only for building, supporting and reviewing your system. Access is logged. The named subprocessor list covers every third party that can process your data.
Every interaction is logged, so we can show you exactly what happened and why. Liability, indemnities and the incident process are set out in the Master Services Agreement — read them before signing, and bring your legal team to the scoping call if the deployment is sensitive.
Request the DPA and security pack before you book anything. If the answers do not work for you, you have lost an email rather than a quarter.