Private company workspaces
A subscription provisions a dedicated workspace with its own configuration, users, roles and operational records. One customer's employees, payroll, customers and tickets are not presented alongside another customer's.
Tork is built so that a company's operational data stays inside its own workspace, people only reach what their permissions allow, and sensitive actions leave a record. This page explains how that works — in the plain terms an IT or security reviewer needs before an evaluation.
What this page is. A description of Tork's security architecture and access model. It is not a certification claim. Where Tork holds no formal third-party attestation, this page says so plainly — see what we do not claim.
Tork is a multi-tenant platform built around separation rather than shared tables with a filter column. Provisioning a subscription creates the company's own workspace, and tenant business data is designed around a separate database per subscribing company.
A subscription provisions a dedicated workspace with its own configuration, users, roles and operational records. One customer's employees, payroll, customers and tickets are not presented alongside another customer's.
Tenant business data is designed around a separate database per subscribing company rather than one shared pool of rows. A query scoped to the wrong customer is an architectural impossibility rather than a bug waiting to happen.
The public marketing site does not connect to tenant databases. Signup, plan catalog and support requests travel through protected server-side API flows to Tork Control, signed and validated on the server — never from browser JavaScript.
API keys, signing secrets and credentials are held server-side in environment configuration. They are not embedded in pages, bundled into browser JavaScript, or exposed through public endpoints.
Being on a plan that includes a capability is not the same as being allowed to use it. Tork evaluates both: whether the company's subscription includes the feature, and whether this particular user is authorized for this particular action.
Feature entitlement (what the plan includes) and user authorization (what this person may do) are checked independently. Enforcement is applied at the menu, page, action and server levels rather than by hiding a link in the interface.
Users receive one base role, optional permission packs for a business area, and an access scope. Finance access does not silently grant HR, payroll or project access. Read-only auditor access is available where oversight is needed without change rights.
Payroll and payslip access requires the appropriate authenticated permissions. Employees are designed to reach their own published payslips through self-service; company-wide payroll control is a separate, explicitly granted permission.
Tenant files — employee documents, attachments, uploads — are kept outside the public web root and served through controlled application interfaces that apply the same permission checks as the rest of the workspace. There is no guessable public URL for a private document.
Sensitive operational actions are designed to be auditable, so access changes and significant operational events can be reviewed after the fact rather than reconstructed from memory.
Human support is designed around explicit request and ownership: a visitor or customer asks for a person, a single support agent takes ownership, and support work is associated with that conversation or ticket rather than with open-ended access to a customer's workspace.
Signup collects company and owner details, then hands the payment step to Stripe's hosted checkout. Tork stores subscription and billing references returned by the payment processor, not raw card data.
Where card data lives. Tork does not operate its own card vault. Payment processing is handled by Stripe as the payment provider. Any PCI-DSS obligations met by that processor are the processor's, and Tork does not represent them as its own certification.
Subscription state, plan entitlement and billing lifecycle are administered in Tork Control, separately from the public marketing site.
Security pages are easy to inflate. These are the claims Tork is not making on this page, so nothing here has to be walked back during a procurement review.
| Claim | Tork's position today |
|---|---|
| SOC 2 (Type I or II) | Not claimed. Tork does not present a SOC 2 attestation.No SOC 2 report is offered or implied. |
| ISO 27001 | Not claimed. Tork does not present an ISO 27001 certification. |
| HIPAA / GDPR "certified" | Not claimed. GDPR has no certification of this kind, and Tork makes no HIPAA compliance claim.Data-handling practices are described in the privacy notice. |
| PCI-DSS certification | Not claimed by Tork. Card processing is handled by the payment provider. |
| Guaranteed uptime / formal SLA | No public uptime percentage or contractual SLA is published on this site.Service commitments, where offered, are agreed in writing. |
| Data residency in a named region | No specific residency guarantee is published here. Raise residency requirements during discovery. |
| Penetration-test certification | No third-party penetration-test certificate is published on this site. |
If your evaluation requires any of the above, tell us during discovery and we will answer directly about what exists, what is in progress and what does not exist today.
We would rather answer a hard security question early than discover it after a rollout has started.