Cowork AI Security Policy
Last Updated: 23 July 2026
1. Introduction
At Cowork AI, security is a fundamental part of our platform design and operations. We are committed to protecting customer information, business data, AI agent configurations, conversations, and platform resources through appropriate technical and organisational safeguards.
This Security Policy describes the measures we take to protect information processed through our Services.
2. Security Principles
Cowork AI follows these core security principles:
Confidentiality
Customer information is only accessible to authorised users, systems, and service providers required to deliver the Services.
Integrity
We implement controls to prevent unauthorised modification, loss, or corruption of customer data.
Availability
We design our systems to provide reliable access to the Services while protecting against service disruptions.
3. Data Protection and Encryption
Data in Transit
All communications between users and Cowork AI services are protected using industry-standard encryption protocols, including HTTPS/TLS encryption.
Examples include:
- Dashboard access
- API communications
- Third-party integrations
- Data transfers
Data at Rest
Customer data stored within our systems is protected using encryption mechanisms provided by our cloud infrastructure providers.
This may include:
- Customer profiles
- AI agent configurations
- Conversation transcripts
- Call metadata
- Integration settings
4. Access Control
Cowork AI applies access controls designed around the principle of least privilege.
Security measures include:
- Role-based access controls
- Restricted administrative access
- Multi-factor authentication where available
- Unique user accounts
- Removal of unnecessary access privileges
Employees and contractors only receive access required to perform their responsibilities.
5. Customer Account Security
Customers are responsible for maintaining the security of their accounts.
Customers should:
- Use strong passwords
- Enable multi-factor authentication where available
- Protect login credentials
- Immediately report suspicious activity
Cowork AI will never request customer passwords.
6. AI Agent Security
AI agents created through Cowork AI may process customer interactions and business information.
Security controls include:
- Controlled access to agent configurations
- Separation between customer environments
- Restricted modification permissions
- Monitoring of agent activities
- Protection of customer-provided knowledge sources
Customers remain responsible for reviewing AI agent responses and ensuring appropriate business rules are applied.
7. Voice Data and Call Security
Depending on customer configuration, Cowork AI may process:
- Voice conversations
- Call recordings
- Transcripts
- Caller information
- Appointment information
Security practices include:
- Secure transmission of voice data
- Controlled access to recordings and transcripts
- Configurable retention periods where available
- Protection of stored conversation data
Customers are responsible for complying with applicable call recording and consent laws.
8. Third-Party Provider Security
Cowork AI integrates with trusted third-party providers, which may include:
- Cloud infrastructure providers
- AI model providers
- Voice technology providers
- Telecommunications providers
- Payment providers
These providers maintain their own security controls and compliance programs.
Cowork AI evaluates third-party services based on factors such as:
- Security practices
- Reliability
- Data handling processes
- Privacy commitments
9. Data Residency
Cowork AI aims to support Australian businesses by using infrastructure and service providers that offer appropriate regional hosting options where available.
Some third-party AI and telecommunications services may process data internationally depending on customer configuration and provider architecture.
Customers should review third-party provider privacy terms for additional details.
10. Vulnerability Management
We take reasonable steps to identify and address security vulnerabilities through:
- Software updates
- Dependency management
- Security reviews
- Infrastructure monitoring
- Access reviews
Security issues identified internally or reported by customers are assessed and prioritised based on risk.
11. Logging and Monitoring
Cowork AI may maintain security logs relating to:
- Account activity
- Authentication events
- Platform operations
- System errors
- Service usage
Logs are used for:
- Security monitoring
- Troubleshooting
- Fraud prevention
- Platform improvement
12. Incident Response
If Cowork AI becomes aware of a security incident affecting customer information, we will:
- Investigate the incident
- Take steps to contain and remediate the issue
- Assess impact
- Notify affected customers where appropriate and required by law
13. Data Retention and Deletion
Customer data is retained only for as long as required to provide the Services or meet legal obligations.
Customers may request deletion of eligible data according to applicable agreements and privacy requirements.
Upon account termination:
- Access may be disabled
- Customer data may be deleted after applicable retention periods
- Backups may remain temporarily until securely overwritten
14. Employee Security
Cowork AI maintains organisational controls including:
- Access restrictions
- Confidentiality obligations
- Security awareness practices
- Appropriate handling of customer information
15. Responsible AI Practices
Cowork AI encourages responsible use of AI systems.
Customers should ensure:
- AI agents clearly identify themselves when required
- AI-generated information is reviewed where appropriate
- Sensitive decisions are not made solely by AI systems
- Customer privacy requirements are respected
16. Reporting Security Issues
If you discover a security vulnerability or suspicious activity, please contact:
Security Team
Cowork AI
Email: support@coworkai.au
Please include:
- Description of the issue
- Steps to reproduce
- Potential impact
- Relevant technical details
We will review and respond appropriately.
17. Policy Updates
Cowork AI may update this Security Policy periodically to reflect changes in technology, services, or security practices.
The latest version will always be published on our website.