Skip to content

Trust

You are putting audit evidence in here. Here is what happens to it.

A quality platform asks you to move the records you will be judged on. That deserves plain answers, not a badge wall.

Where the data lives

Hosted in the European Union. Or on your own infrastructure, if a client contract requires project data to stay inside your walls — the software is the same either way.

Who can reach it

Access is by role and by project. A client user sees the project they are a party to and nothing adjacent to it. An inspector sees the work assigned to them. This is enforced on the server, not by hiding buttons in the interface — a distinction that matters, because hidden buttons are not a control.

What gets recorded

Who did what, when, and against which revision of the rule that applied at the time. Records that have been issued are not edited in place: a correction produces a new revision that supersedes the old one, and the old one remains readable. That is what makes the history usable in an audit rather than merely present.

Sealed documents

Issued certificates and reports are sealed and can be verified by a third party without contacting you — a QR code on the document resolves to a public verification page. Anyone holding the paper can confirm it is genuine and still valid.

Getting it back out

Full export, in open formats, including the sealed documents and their verification records. No notice period, no per-export fee. A record you cannot take with you is not a record you own — ask this question of every vendor you talk to, including us.

What we do not claim

We are a young product. We do not hold ISO 27001, and we will say so rather than imply otherwise with vague wording. If your procurement requires a certified supplier today, we are not it yet. If it requires a supplier who can answer these questions precisely, we are.

Reaching us about security

Write to security@worgify.com. Reports of suspected vulnerabilities are answered, not ignored.