Security at BobsWork

How we protect your business data, conversations, and wallet balances.

Data Encrypted at Rest and in Transit

Every BobsWork page serves over HTTPS-only with HSTS preload. Data is encrypted in the database with the same Postgres-encrypted-at-rest offered by Neon. Backups inherit that encryption and a 30-day retention policy.

Authentication Is Built for Executives

Every account ships with multi-factor ready out of the box. We recommend turning it on the day you sign in. We never store passwords in plaintext — bcrypt hashing only — and we never email them back.

Set up MFA →

Permissions Are Workspace-Scoped

Workspaces are isolated. Members see only what their role allows, and every permission change is recorded in an append-only audit log your admin can review at any time.

Open Security Center →

Payments Run on Stripe Connect — Never Stored Here

BobsWork never touches raw card numbers. All payment flows run on Stripe Connect in our merchant or marketplace model, with Webhook signatures verified on every Stripe event we accept.

Privacy Policy

Read the full privacy policy for details on what we collect, how we use it, and how you can export or delete it.

Read the privacy policy →

Report a vulnerability

Email security@wiseman.life with reproduction steps. We respond within one business day.

Compliance

GDPR-aligned data handling and deletion. SOC-style controls on the platform ops side, including immutable audit log and force-revocation.

Uptime & incidents

Status updates posted to status.bobswork.co. Subscribe for incident notifications.