Short answers to the questions security, privacy and works-council reviewers ask about 20xwork. Every answer is a commitment we sign in the contract. If a question is missing, write to adharsh@20xwork.ai.
Customer data is not used to train or tune any model, by us or by the model providers we use. The only way in is a written opt-in to our Development Partner Programme, using de-identified signals, which you can leave at any time.
No screens, keystrokes, private messages or personal accounts. Signals come from the work tools your organisation connects, at the record level.
Each employee can see what was read about their work, the evidence behind every level, and every recommendation they were given.
On request or at termination, all customer data is deleted from live systems within 30 days, with written confirmation.
It reads how work is done in the tools your organisation connects. It never records screens, keystrokes, private messages or personal accounts.
Yes. Every person sees their own profile, the evidence behind it, and every recommendation they were given.
No. It recommends, a person decides. Profiles are evidence-backed, visible to the person, and never the sole basis for a decision with legal or similar effect.
No. We do not collect device location. Sign-in records carry a country derived from IP address for security only.
Work signals from the tools your organisation connects, the recommendations we make, and what happened next. Nothing from personal accounts, and nothing from tools you have not connected.
Work signals and recommendations for the life of the subscription; transient request data not at all; everything deleted within 30 days of termination.
Yes on Enterprise. Work signals can be limited to as little as 90 days from the source event; profiles then rest on the window you choose.
Not by default, on any plan, and not by the model providers we use. The only way in is the 20xwork Development Partner Programme, by written agreement, and you can leave it at any time.
No. Every profile, pattern and recommendation is computed inside your organisation's own data. Only de-identified signals from Development Partner Programme members are ever combined, and only to improve 20xwork's models.
United States by default, on Microsoft Azure. European Union hosting is available on Enterprise.
Systems of record such as Salesforce at the record level, AI assistants through their admin usage exports, process tools for step definitions. Each connection is listed with its scope and can be revoked by your admin.
It is used for the moment it takes to match your task to a step and build the card, then discarded. It is not stored and not used to train anything.
Encrypted in transit and at rest, single-tenant scoping at the database layer, least-privilege access, audit logs, and annual penetration testing.
Named engineers, for a stated reason, for a limited time, with every access logged. Support staff see only what you show them.
Contain, assess, notify affected customers within 72 hours of confirmation, and publish a root cause.
Single sign-on through your identity provider, multi-factor enforced by your provider, SCIM provisioning on Enterprise, and role-based access inside the product.
Every sign-in, connection change, export, deletion, admin view-as, and every access by 20xwork staff, kept 12 months and exportable.
99.9% monthly availability on Enterprise, encrypted daily backups kept 30 days, recovery point of 24 hours and recovery time of 8 hours, tested twice a year.
Yes. On request, or automatically at termination, within 30 days, with written confirmation.
Yes. Removing a seat deletes that person's profile, signals and recommendations within 30 days.
Admins can export profiles, signals, recommendations and outcomes as CSV and JSON at any time.
Your organisation is the controller; we support you within 10 business days.
Open your profile in the product to see and export everything held about you. Deletion goes through your organisation's admin, because your organisation is the controller.
A processor. Your organisation is the controller and decides what is connected, who has a seat and how the output is used.
It is part of every commercial agreement. A countersigned copy is available on request.
Processor under Article 28, Standard Contractual Clauses for transfers, EU hosting available, and a named contact for supervisory authorities.
We require valid legal process, notify you unless prohibited, challenge overbroad requests, and publish a count each year.
What we collect from website visitors and customer contacts, why, and your rights.
One analytics cookie on the website with IP truncated, and the session cookies needed to keep you signed in to the product. No advertising cookies, no third-party trackers.
Language models write the card text and judge next steps; the facts behind them come from your organisation's own data; every AI output is labelled and a person always decides.
SOC 2 Type II in progress, on a published timeline. Controls follow SOC 2 and ISO 27001 today. Reports and questionnaires under NDA.
One address for all of it: adharsh@20xwork.ai, read by a founder. Acknowledged within 2 business days.
Send us your SIG, CAIQ or your own template and we will return it completed, with our penetration test summary and policies under NDA.