Skip to content
Security and trust

Built for sensitive operational knowledge.

What your people know is as sensitive as anything in your databases. You decide who can ask what, every answer has a name behind it, and nothing is shared without sign-off.

Request a demo
Security & trust

You decide who can ask what.

Every answer has a name behind it, and nothing is shared without sign-off. Controls are built into how knowledge is captured, checked, and shared.

A name behind every answerSource-backed answersYou decide who can ask whatNothing shared without sign-offAudit-ready by designSecurity-first architecture
Trust, in practice

What stands between a capture and the person who inherits it.

  1. 01 Private first

    New knowledge starts private. Nothing is shared raw.

  2. 02 Checked by a person

    Someone your team trusts checks every item. Sensitive context can be restricted or redacted.

  3. 03 Signed off

    Nothing reaches a successor until a human signs off.

  4. 04 Kept safe

    What your org confirmed stays put, with change records.

  5. 05 Accountable

    Transfer receipts keep every handoff accountable after the fact.

Implemented today

Least-privilege by default

Every request is scoped to its organization and role. People see only the company memory they are cleared to use.

Role-based permissions

Scoped roles for workflows, reviewers, and recipients keep context on a need-to-know basis.

Approved knowledge only

Nothing reaches a successor until a human reviews and approves it.

Source citations

Every answer points to the file, ticket, or person it came from.

Human review and redaction

Reviewers can restrict, redact, or exclude sensitive context before it is shared.

Encrypted in transit and at rest

Company data is encrypted while it moves and while it is stored. Privileged credentials stay server-side.

Receipts and change records

Confirmed knowledge stays put, with transfer receipts and change records, audit-ready by design.

Responsible AI

Permission-aware retrieval with no invented company history. Answers are grounded in real sources.

On the roadmap

  • SSO and SCIM provisioning
  • Customer-controlled retention policies
  • Expanded enterprise administration
  • Expanded AI governance and human oversight

Honest about where we are

We are transparent about where we are. WorkFera does not currently claim SOC 2, ISO 27001, HIPAA, or GDPR certification. We are glad to walk your team through our current controls and roadmap.

How we design for trust

Four rules that shape every capture.

Collect only what a workflow needs

Capture is scoped to the workflow. We do not vacuum up everything by default.

Preserve source context

Every captured item keeps a link to where it came from, so it can always be verified.

Review before broad access

Knowledge is reviewed and approved before it is shared with a successor.

Easy to restrict

Sensitive knowledge can be restricted, redacted, or excluded at any point.

Security FAQ

Common questions

Are you SOC 2, ISO 27001, HIPAA, or GDPR certified?

Not currently. We are transparent about where we are and will walk your team through our current controls and roadmap. We do not claim certifications we have not completed.

Do you need access to all of our systems?

No. You choose which sources Fera can read on a per-workflow basis. Access is least-privilege by default and revocable at any time.

Will our knowledge be used to train shared models?

No. Your knowledge is yours. Retrieval is permission-aware and grounded in your own sources, with no invented company history.

Who can see captured knowledge?

Only the people you scope into a workflow. Roles for contributors, reviewers, and recipients keep context on a need-to-know basis.

Fera

Name the person you can't lose.

Tell us the role, project, or system keeping you up at night, and we will build the walkthrough around it.

No canned tour. Just your scenario and a clear next step.