MyWorkBase
Features Pricing Home
Security & Trust

Keeping your data safe

Last reviewed: 13 July 2026

Your business data — and your own customers' and subcontractors' information — is exactly the kind of data that has to be looked after properly. This page explains, in plain terms, the measures we take to protect it in MyWorkBase. We follow a defence-in-depth approach: several independent layers of protection, so your data never relies on a single safeguard.

At a glance

  • Hosted in the UK on ISO 27001-certified infrastructure
  • Encrypted in transit (HTTPS/TLS) and encrypted, off-site backups (AES-256)
  • Each business's data is fully separated — you only ever see your own
  • Key-only administrator access; passwords are never stored in plain text
  • Firewalled, automatically patched servers with active intrusion prevention
  • Application code security-reviewed and hardened against common attacks
  • Automated backups every hour, held off-site and encryption-protected
  • Card payments via Stripe — we never hold your card details

1. Where your data is stored

MyWorkBase and your data are hosted in the United Kingdom on infrastructure certified to ISO/IEC 27001 — the international standard for information-security management. Keeping data in the UK also means it stays within UK data-protection law.

2. Encryption

In transit: every connection to MyWorkBase is protected with HTTPS/TLS encryption, so information moving between your device and our servers is protected from being read along the way. If anyone tries to reach the app over an unencrypted (http) address, they're immediately redirected to the secure (https) version, and their browser is told to use the secure connection every time after that.

At rest: our backups are protected with AES-256 encryption, and the keys are held only by us — a backup copy on its own would be unreadable without them.

3. Your data is kept separate

MyWorkBase is built so that each business's information is isolated. Every record is tied to the account that owns it, and the system is designed to only ever return your own data to you, so one customer cannot browse or reach another customer's information — and that separation is preserved in our backups too.

4. Secure access and sign-in

  • Administrator access is by cryptographic key only. Password logins to the server are switched off entirely, and remote "root" (full-control) access is disabled.
  • Passwords are never stored in readable form. Account passwords are protected using bcrypt one-way hashing, so even we can't see them.
  • Instant sign-out everywhere. Changing your password immediately ends any other active sessions.
  • Brute-force protection. Repeated failed sign-in attempts are rate-limited and blocked.

5. A hardened, monitored server

  • Firewalled by default. The server refuses all incoming connections except the few that are genuinely needed (secure web traffic and protected admin access).
  • Databases are not exposed to the internet. They can only be reached by the application itself, never directly from outside.
  • Automatic security updates. The server keeps itself patched against newly discovered vulnerabilities.
  • Active intrusion prevention. Repeated malicious attempts are detected and the offending source is automatically blocked.

6. Backups and disaster recovery

Your data is backed up automatically every hour. Backups are encrypted, stored off-site from the live server, and retained so we can recover from an earlier point if ever needed. Database backups are taken cleanly and consistently, so a restore brings everything back intact.

7. Secure development and change control

Our application code has been through an in-depth security review, including adversarial (red-team-style) verification, and is hardened against common web-application attacks. Every change to the live system is reviewed and logged before it goes out, so changes are checked before they get anywhere near your data.

8. Payments

Card payments are taken by Stripe, a global PCI-DSS-certified payment provider. Your card details are handled entirely by Stripe's hosted payment system and never touch our servers — we never see or store them.

9. Data protection and your rights

We handle personal data in line with the UK GDPR and the Data Protection Act 2018, and we're registered with the Information Commissioner's Office (ICO) under reference ZC188926. When you use MyWorkBase to store information about your own customers or subcontractors, you remain in control of that data and we act as your data processor. Full details are in our Privacy Policy.

10. Our ongoing commitment

Security isn't a one-off task — it's something we maintain. We review our protections regularly and strengthen them as new threats emerge and best practice moves on. Your data is protected by multiple independent safeguards working together, and we treat it with the same care we'd expect for our own.

If you have any questions about security or data protection, email us at info@azurydigital.co.uk.

MyWorkBase
PrivacyTermsSecurity
MyWorkBase is a product of Azury Digital & Tech Solutions Ltd — a company registered in England and Wales (no. 13446812), registered office 23a The Precinct, London Road, Waterlooville PO7 7DT. ICO registration ZC188926.
© 2026 Azury Digital & Tech Solutions Ltd. All rights reserved.