Security

Built to protect sensitive operational data

Anywrks is built for human services organizations managing sensitive workforce, compliance, housing, and program information. We use established security controls and trusted infrastructure to protect that information across the platform.

Your organization owns its data

Your organization retains ownership of the information and records entered into Anywrks. We process that information only to provide, secure, maintain, and support the platform.

We do not sell customer data, use it for advertising, or share it with advertising networks.

Security through trusted infrastructure

Anywrks is built on established cloud, database, storage, and authentication infrastructure. These services provide security capabilities such as encryption, secure authentication, access controls, backups, and infrastructure monitoring that Anywrks uses as part of protecting customer data.

Where our infrastructure providers maintain independent security certifications or audits, those certifications apply to their services and infrastructure, not to Anywrks itself.

Encryption

Data protected at rest

TLS

Data protected in transit

Access Controls

Restricted by role

Secure Authentication

Protected account access

How your data is protected

Encryption at Rest & in Transit

Customer data is protected using encryption capabilities provided by our managed infrastructure. Information transmitted between your browser and Anywrks is protected using HTTPS/TLS. Stored database records and files are protected using encryption-at-rest capabilities provided by our infrastructure. Sensitive information is never intentionally stored or transmitted in plain text where encryption controls are available.

Secure Authentication

Anywrks uses managed authentication infrastructure to protect account access. Authentication protections include secure credential handling, session management, account verification, and additional authentication controls where enabled. Passwords are not stored by Anywrks in plain text.

Role-Based Access Control

Anywrks is designed to keep information separated by organization and restrict access based on a user's permissions. Depending on the workspace and role: users can access only authorized organizational information; staff access can be limited to appropriate programs and responsibilities; administrative functions are restricted to authorized users; and sensitive information can be restricted based on permissions. Access to production customer information by Anywrks personnel is limited to authorized individuals when necessary for support, security, or platform operations.

Organization & Data Isolation

Customer accounts are logically separated so one organization cannot access another organization's records through normal use of the platform. Anywrks combines application-level permissions, authentication, and database access controls to enforce organizational boundaries.

Audit Activity

Important activity within Anywrks may be recorded with information such as the user, action, and timestamp. This may include account access, record changes, assignment and status changes, document activity, administrative actions, and other important workspace activity. These records support security investigations, operational oversight, troubleshooting, and audit readiness.

Backups & Recovery

Anywrks uses managed database and storage infrastructure with backup and recovery capabilities. These protections are designed to reduce the risk of data loss and support restoration following an unexpected operational event. Backup and recovery capabilities may vary based on the underlying service and configuration.

Infrastructure Security

The infrastructure supporting Anywrks is operated by established technology providers that maintain their own security programs, controls, monitoring, and compliance practices. We evaluate the services we rely on for their security posture and use available security capabilities appropriate to Anywrks. Any certifications held by our infrastructure providers apply to those providers and do not represent certification of Anywrks itself.

Incident Response

Anywrks maintains processes for identifying, investigating, containing, and responding to suspected security incidents. If an incident affects customer information, we will notify affected organizations as required by applicable law and contractual obligations.

Responsible Disclosure

If you believe you have discovered a security vulnerability in Anywrks, please contact us at peacemakerbak@gmail.com. Please provide enough information for us to understand and reproduce the issue when possible.

How we handle sensitive information

Workforce & Compliance Information

Organizations may use Anywrks to manage information such as CPR and First Aid certifications, driver's licenses, training records, professional credentials, background-check status, medication certifications, expiration dates, and employee onboarding and compliance information. Access to this information is restricted to authorized users within the organization.

Housing Information

Organizations may use the Housing workspace to manage information such as intake and admission activity, service authorizations, tenancy status, service scheduling, MCO-related operational information, billing readiness, and program tasks and deadlines. Access is controlled according to the organization's users and permissions.

Support Coordination Information

Organizations may use Anywrks to manage participant caseloads, monitoring visits, ISP deadlines, plan renewals, service authorizations, participant follow-ups, monthly contacts, and assignments and operational status. Organizations remain responsible for determining what information is appropriate to enter into Anywrks and who should have access to it.

Documents & Files

Files stored through Anywrks use managed storage infrastructure with access controls designed to prevent unauthorized access. Documents are made available only through authenticated or otherwise authorized platform workflows.

Protected Health Information

Unless Anywrks and an organization have entered into the appropriate written agreement addressing HIPAA requirements, including a Business Associate Agreement where required, Anywrks should not be used to store or process Protected Health Information in a manner that requires Anywrks to act as a HIPAA Business Associate.

Additional security practices

  • Customer information is not sold or used for advertising
  • Passwords are never intentionally stored in plain text
  • Authentication sessions are securely managed
  • Access is restricted by organization and user permissions
  • Production access is limited to authorized personnel
  • Sensitive information is protected using managed encryption capabilities
  • Platform activity may be logged for security and audit purposes
  • Managed infrastructure provides backup and recovery capabilities
  • Third-party infrastructure is evaluated for security and reliability
  • Dependencies and infrastructure are maintained as part of ongoing platform operations

Security questions or concerns?

If you have a security question, want to report a vulnerability, or need information for your organization's security review, contact us directly.

Contact Security Team