Skip to main content

Workiva Security

Maximize security and privacy.

Workiva utilizes numerous measures to ensure the utmost in data security and privacy.

Main Spreadsheet 139720 AICPA SOC 2 AICPA SOC 1 Type II ISO 27001 GDPR **********

Committed to Compliance.

 

Security Logos

Compliance Certifications and Memberships

SOC 1 Type II

Workiva undergoes  SOC 1 (System and Organization Controls) Type II reporting three times a year with a control period of

October 3 through October 2

January 1 through December 31

April 1 through March 31

The SOC 1 audit is conducted by an independent third party, establishes that Workiva employs uniform and reliable operational controls and safeguards as a host and processor of data belonging to its customers. Updated SOC reports are available with ND

SOC 2 Type II

Workiva undergoes SOC 2 (System and Organization Controls) Type II reporting annually. The SOC 2 audit is conducted by an independent third party, which establishes that Workiva employs uniform and reliable operational controls and safeguards as a host of data belonging to its customers.

Workiva SOC2 Type II report is unqualified; with a control period that covers October 3 through October 2.

Woriva also includes controls around HIPAA and GLBA for our customers' regulatory requirements

ISO/IEC 27001:2022

Workiva is ISO/IEC 27001:2022 certified.

Download Certificate

CSA STAR

Workiva is listed on the Cloud Security Alliance (CSA) STAR registry, showcasing our transparency and adherence to industry leading cloud security best practices.

See Workiva on CSA STAR Registry

FedRAMP Moderate

Under the Federal Risk and Authorization Management Program, Workiva has achieved FedRAMP Moderate. This means we are DOD IL2 compliant.

Workiva has also completed CMMC 2.0 L1 Self-Assessment requirements.

Authorization Details

 

Privacy Policy

Workiva complies with applicable data protection laws regarding the collection, use, and processing of personal information, including the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

Workiva has published privacy policies for our public website and services (Workiva Platform). Workiva is an active participant of the EU-US Data Privacy Framework (DPF), the UK Extension to the EU-US DPF, and the Swiss-US DPF, as verified by TRUSTe

Website privacy policy: https://www.workiva.com/legal/workiva-privacy-policy 

Services (Workiva Platform) privacy policy: https://www.workiva.com/legal/services-privacy-policy

DPF: https://www.dataprivacyframework.gov/list

TRUSTe verification: https://privacy.truste.com/privacy-seal/validation?rid=6ede40d9-1850-466a-b0ef-e2382237fcbe

HIPAA Workiva enables covered companies subject to the Health Insurance Portability and Accountability Act of 1996 in the United States (HIPAA) to use Workiva's cloud productivity platform to mitigate risk, improve productivity, and give users confidence in data-driven decisions.

 

Cloud Security Alliance

The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment.

Please see our CAIQ

 

Cloud Security

diagram of the workiva platform architecture showing integrations and capabilities

Facilities

Workiva uses secure data hosting with secure servers and applications. Our office locations have no data centers or access to data centers. Workiva utilizes Amazon Web Services (AWS) for IaaS (Infrastructure as a Service) and PaaS (Platform as a Service).

Our offices are restricted facilities with badge access, cameras, segregated areas and a visitor policy which requires guests to be escorted, sign in and confidentiality agreements. We also implement secure document handling and screen protection to mitigate shoulder surfing. Rooms that store telecommunication and network equipment are kept locked and alarmed.

Data Hosting Location

The Workiva Platform offers 4 data hosting locations for customer data. Data center locations are listed below.

apac.wdesk.com stores data in AWS data centers in Japan

app.wdesk.com stores data in AWS data center in the United States in Northern Virginia.

eu.wdesk.com stores data in AWS data centers in Ireland

ca.wdesk.com stores data in AWS data centers in Canada

More information on AWS can be found here: https://aws.amazon.com/about-aws/global-infrastructure/

Data Center Security Workiva has partnered with Amazon for infrastructure and cloud services. Workiva utilizes Amazon Web Services (AWS) for IaaS (Infrastructure as a Service). Workiva performs an annual third party risk assessment of AWS, including a review of third party audit reports to evaluate the effectiveness of their data center security.

 

Dedicated Security Team Workiva has a security program and dedicated team with a Chief Information Security Officer (CISO).
Network Vulnerability Scanning Workiva utilizes various internal security tools to perform weekly internal network vulnerability scans against all production environments. Additionally, external networks scans are performed using open source tooling as a routine part of our third-party penetration tests.
Third-Party Penetration Tests To ensure customers can rely on our testing, Workiva also engages a CREST certified third-party security firm to perform vulnerability and penetration at least annually.
Security Incident Event Management Workiva utilizes a Security Information and Event Management (SIEM) tool called Splunk to perform continuous monitoring and log aggregation. Workiva’s Information Security Team reviews logs and alerts for performance and security considerations including logs relating to authentication, endpoint, web application, and more from the logging generated by our wide array of security tools. Logs are stored on a central logging system, transmitted over an encrypted channel, encrypted at rest and segregated from other systems and users. Logs cannot be modified once written and deletion of log is monitored. Logs are continuously monitored for abnormalities and investigated per our standards and policies. Our alerts are continuously reviewed for accuracy, coverage and effectiveness. Playbooks are developed and maintained to standardize and improve response. This data is used to perform investigations of reported security events and incidents.
Intrusion Detection and Prevention Workiva deploys Crowdstrike Falcon's Next Generation AV to all user endpoints and server infrastructure to provide active threat protection against known and emerging threats. Additionally, Cloud Security Posture Management and Cloud Workload Protection tools are deployed across the application infrastructure to provide host based intrusion detection. Workiva also employs multiple AWS services including AWS GuardDuty, Cloudtrail and Cloudwatch to continuously monitor our AWS accounts for malicious activity too. The Workiva Platform itself also leverages logging capabilities and supporting systems to monitor for potential threats within our SIEM tool Splunk.
DDoS Mitigation Workiva leverages both Network Firewalls and Web Application Firewalls (WAF) to perform ingress filtering and attack prevention at the network boundary. Direct access to internal resources is prevented through the use of private Virtual Private Clouds (VPCs). Additionally, Workiva has deployed Distributed Denial of Service (DDoS) protection services for all applications running in the cloud environment.
Security Incident Response

Workiva has an established Incident Response Policy, standard and procedures which outlines actions, notification, and steps for remediation in the event of any type of incident beyond normal business operations. This plan is tested annually for security events.

Workiva's Information Security team recognizes the need to be alert to external risks and is vigilant in looking for potential issues. We also employ active monitoring of key information used to identify threats. After proper investigation from the Workiva Information Security team, an event may be classified an incident and escalated through appropriate channels, including executive management, legal counsel, and additional support as needed.

 

Encryption in Transit Workiva uses TLS versions 1.2 and 1.3 with digital certificate identification. In addition, Workiva platform utilizes HTTP Strict Transport Security (HSTS) for enhanced protection.
Encryption at Rest All Workiva Platform data is stored encrypted with Advanced Encryption Standard (AES) 256-bit algorithm.

 

Uptime

Workiva provides status through our Status Page.  

Through our Service Level Agreement (SLA) within contracts Workiva commits to a 99.5% uptime.

Redundancy Workiva relies on multiple data centers (multiple availability zones within your selected region) and office locations to provide operational redundancy. We ensure reliability by distributing and replicating data across our multiple systems in case of failure at any single point.
Disaster Recovery The Workiva Platform includes high availability through our redundant infrastructure.

 

Application Security

Secure Code Training Workiva has mandatory security awareness training for anyone with access to Workiva systems. Additional role specific training is provided as needed. Training is required at the initial time of access and on an annual basis thereafter. Training includes policies, standards, confidentiality and privacy, physical security, system security, acceptable use, AI and social engineering and other items.
Framework Security Controls Workiva leverages modern and secure open-source frameworks with security controls to limit exposure to OWASP Top 10 security risks. These inherent controls reduce our exposure to SQL Injection (SQLi), Cross Site Scripting (XSS), and Cross Site Request Forgery (CSRF), among others.
Quality Assurance

Workiva has a detailed change control process governed by the Information Security Policy that applies to all changes to the environment, including configuration, operating system, and application updates. New versions of the Workiva Platform, or updates designated for release, are moved from the development environment and staged within a mirrored production environment where our Quality Assurance Team performs rigorous system, integration, regression, and acceptance testing. This environment is also where ongoing penetration testing and vulnerability scanning is performed.

Security is part of all phases of product development. Code pertaining to session management, access control, APIs that perform cross-platform calls, authentication, input validation, output encoding, secure transmission, audit logging, file uploads, XSS/CSRF protection, or encryption/hashing has security review either by the Information Security team or developers trained and authorized in security review. Code changes and additions are tracked, reviewed, and approved by security production release. The Information Security team utilizes OWASP Top 10 among other industry standards for secure coding.

Great care is taken during the design and prototyping phases of any feature set to identify architecture and implementation that may require security consideration. New feature sets requiring security consideration are subject to code review and approval prior to production release.

Separate Environments Development and Testing environments are separated from the Production environment. Additionally, segregation of duties principles are implemented throughout Workiva to enforce checks and balances and minimize risk.

 

Dynamic Vulnerability Scanning Workiva has configured a Dynamic Application Security Testing (DAST) tool to perform regularly scheduled dynamic vulnerability scanning. In addition to automated scanning, Workiva performs security testing as a part of the SDLC release process.
Static Code Analysis Workiva has configured a Static Application Security Testing (SAST) tool to perform regularly scheduled scans to identify potential weaknesses in application code. In addition to automated scanning, Workiva performs secure code reviews as a part of the SDLC release process.
Third-Party Penetration Testing CREST-certified firm engaged at least annually.
Responsible Disclosure / Bug Bounty Program

Workiva leverages a bug bounty platform which maintains a curated set of active professional security researchers who provide continuous security coverage of the Workiva Platform. Workiva also maintains a security.txt page to direct interested external parties on responsible disclosure.

Report a Vulnerability

 

 

 

 

Product Security

Authentication Options

User access is governed by a membership into an Organization, and then memberships into Workspaces, where content is stored and managed. Additionally, content can be permissioned to both an individual, or to a Workspace group. Through our administration application, customers can self-administer usernames and passwords.

Authentication features within the platform also include:

  • Single Sign-On through SAML 2.0
  • User Provisioning via SCIM 2.0
  • Browser Validation
  • Multifactor Authentication (Email)
  • IP Address Restrictions
Password Policy

The Workiva Platform has a minimum standard of twelve (12) characters with no restrictions on special numbers or special characters with a password meter to show strength of user password. Passwords are checked against publicly known breached passwords during login and password setup. These features enable the Workvia Platform to align more closely with OWASP Application Security Verification Standard.

Multifactor Authentication (MFA) The Workiva platform's multi-factor authentication uses email. After setting new password, users will receive an email with a 6-digit code. Users will be required to supply the 6-digit code to complete the login flow.
SSO (Single Sign On) T​he Workiva Platform includes the ability to configure ​i​ndustry standard SAML 2.0​ based S​ingle S​ign O​n solutions, encompassing both IdP and SP initiated login capabilities​ ​​for stringent security measures and seamless user experiences. With SAML 2.0 SSO, users benefit from streamlined access management, fortified security protocols, and enhanced user ​login experience.
SCIM (Server Cross Identity Management) The Workiva Platform offers standard SCIM 2.0 capability with basic authentication to streamline user management, emphasizing data integrity and enhancing security. Our solution automates provisioning and deprovisioning tasks, while maintaining secure access control measures.
Browser Validation The Workiva Platform employs browser validation during login to ensure heightened security measures. Our browser validation verifies the presence of a valid multi-factor authentication (MFA) token, grant only to browsers with authenticated tokens. This validation process enhances security by preventing unauthorized access attempts, reinforcing our commitment to safeguarding user data and maintaining the integrity of our systems.

 

Role-Based Access Controls

Within the Workiva Platform, role assignments can be utilized to gatekeep access to features and functionality. Every member of a workspace has a role, each with its own level of access to features. Based on the solution set for a workspace, you’ll have access to different roles.

Administrative Roles: The Workspace Owner role is only available at the workspace-level. Org Admin roles are available at the organization-level but can perform some functions at the workspace-level

Non-administrative Roles: If your organization is not on the current solution-based licensing model, there are different non-administrative roles such as Editor, Viewer, etc.

Feature Specific Roles: In addition to the roles above, there are roles to provide access to specific features in a workspace. These roles would include content managers, copy managers, task admins, and filing roles

IP and/or Email Domain Restrictions

The Workiva Platform enables the Admin to configure login restrictions to ensure users are authorized from certain IP addresses or email domains, adding an additional layer of security to the platform.

Email Signing (DKIM/DMARC) The Workiva Platform signs outbound messages with DKIM, adheres to a hardfail SPF policy, and runs DMARC in reject mode. Data and attachments are never directly sent within Workiva Platform notifications. Workiva sends all notifications from a fixed set of dedicated IP addresses, and we strongly encourage customers to disable any types of message checking or filtering against messages originating from our platform.

 

Human Resources Security

Policies Workiva has developed a set of risk-based security policies covering a range of topics. These policies are shared with, made available to and provided in trainings to all employees and contractors with access to Workiva information assets.
Training Workiva has mandatory security education training for anyone with access to Workiva systems. Training is required at the initial time of access and on an annual basis thereafter. Training includes policies, standards, confidentiality and privacy, physical security, system security, acceptable use, AI and social engineering and other items.

 

Background Checks Workiva conducts background checks to the extent allowed by law for all employees in accordance with local laws and regulations. The background check may include a criminal record check, employment, education, and references verification.
Confidentiality Agreements Workiva has non-disclosure agreements with employees and third-parties with logical access to systems and information. Information is classified as Public, Private, Sensitive, Highly Sensitive, and/or Restricted, as outlined in the Information Classification Standard.

 

Workiva AI

Workiva AI is built specifically for financial reporting, audit, risk and sustainability. Drive productivity across your teams and unleash their talents on more strategic and high-value work, all while protecting your data. This is offered as an optional feature, giving you the flexibility to opt out as per your organization’s policies and needs.

Tailored: Workiva AI moves beyond basic automation to deliver advanced intelligence through capabilities that anticipate needs and proactively drive workflows.

Human-Centered: Workiva AI is designed to augment human expertise, ensuring humans retain final control and judgment in critical workflows. This approach builds trust and confidence in AI adoption.

Responsible: Workiva AI has an unwavering commitment to building solutions that address the high stakes, auditability, accuracy, and trustworthiness of your work— prioritizing explainability, traceability, and confidence.

Large Language Model (LLM) providers access only the data provided via prompt by Customer users and do not store or retain it. Customer data is not used to train LLMs. All data flows are restricted to API calls only.

Learn About The AI Providers

Sub-processor providers here

Data is encrypted in transit (1.2+). Data is cached until the user manually clears the chat.

Additional security resources.

Security and Compliance Portal
Security Bulletin
Status Page

Online registration is currently unavailable.

Please email events@workiva to register for this event.

Our forms are currently down.

Please contact us at info@workiva.com

Our forms are currently down.

Please contact us at info@workiva.com