SOC2C

Is this your company? Buyers are checking Getworkflex here. Claim getworkflex.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Getworkflex logo

Getworkflex

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Getworkflex is SOC 2 compliant. Getworkflex also holds ISO 27001.

Framework
SOC 2
Auditor
Last report
Renewal
View official trust center ↗

About

WorkFlex supports organisations in making workations and business travel compliant. A software solves all relevant compliance challenges, incl. taxes, labour law, data security and social security. Hundreds of other companies like Vodafone, BioNTech or Flix already use WorkFlex to empower their team to work remotely and travel without compliance risks.

Compliance & infrastructure

Hosting
AWSGCP
Data handled
Customer personally identifiable informationEmployee personally identifiable informationCredit card informationPersonal health information

Subprocessors

10
  • G
    Google Cloud EMEA Limited · gcp
    Frankfurt, Germany
  • M
    Microsoft B.V. · office
    Frankfurt, Germany
  • K
    Kombo Technologies GmbH
    Germany
  • T
    Taktile GmbH
    Germany
  • W
    WorkFlex Germany GmbH
    Berlin, Germany
  • I
    Intercom R&D Unlimited Company · intercom
    Dublin, Ireland
  • L
    Luzmo NV
    Belgium
  • H
    Hetzner Online GmbH
    Germany, Finland
  • C
    Celonis · Data storage and processing
    Germany
  • A
    Amazon Web Services EMEA SARL, Dutch Branch
    Frankfurt, Germany

Compliance leadership

The person who leads Getworkflex's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Getworkflex's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

View our product updates hereMar 2025

https://help.getworkflex.com/en/articles/9939454-product-updates

This listing is partial

5/11 details · 45%

SOC2C shows the verified essentials. 6 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Other certifications
    List your other frameworks (ISO 27001, HIPAA, PCI DSS) the way your trust center does.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Getworkflex SOC 2 compliant?
Getworkflex is SOC 2 compliant. On SOC2C this listing is Listed.
Is Getworkflex ISO 27001 certified?
According to Getworkflex's public trust center, Getworkflex is ISO 27001 certified. On SOC2C this listing is Listed.
Can I use Getworkflex's SOC 2 for a vendor risk assessment?
Yes. Getworkflex's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Getworkflex penetration tested?
Getworkflex hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is Getworkflex secure?
Security isn't a single yes/no, but Getworkflex is SOC 2 compliant. SOC2C verifies its compliance posture and shows how strongly each fact is proven.

Answers published by Getworkflex

Reproduced from Getworkflex's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Is customer data encrypted?
Customer data is secured with 256-bit AES encryption at rest and SSL/TLS encryption in-transit. We currently support TLS 1.2 and 1.3. TLS 1.0 and 1.1 are no longer supported.
Where is the customer data stored and processed?
The customer data is stored in Frankfurt, Germany in a Google Cloud Datacenter. Backups are stored in a separate site at a different hoster in Finland. We provide GDPR-compliant hosting and data processing via our cloud service provider. Customers' data is stored exclusively in the European Union.
How do you use Artificial Intelligence (AI)?
Based on the EU AI Act, all our use of AI is categorized are either considered "minimal risk" or "limited risk". For the detailed AI risk assessments and compliance analysis, please reach out to your WorkFlex Customer Success Manager. Generally, we only use the AI models provided in Google Cloud Platform in our own GCP tenant. Therefore, no data is sent back to the original author of the model during use or as feedback for continued learning. Here is an overview over the features currently implemented: - We use an AI agent in our support chat to help handle some the support requests, if users interacts with the popup it in the bottom right corner in the platform. The agent can access some profile fields like email and name and the trips of the user and also works on the information provided to it directly by the user. (Limited risk). - An AI analytics assistant is available in the analytics dashboards so HR Admins can dynamically edit and generate charts and reports based on anonymized data. (Limited risk) - If the Email-CC integration feature is enabled, there is an AI-based extraction system running that extracts trip information from emails. (Minimal risk) - If the SOS feature is enabled, there is an AI-based translation system translating the alerts from our alert provider to the user's language. (Limited Risk) We are happy to share the AI Risk Assessment documents with you upon request. Going forward, we are planning to add more AI agents working on anonymized data at different parts of the products so clients can interact with them.
How is my data separated from the data of other WorkFlex clients?
Your data is physically separated from the data of other clients. In our database, every client has a separate database schema with separate tables storing only the data for this specific client. In addition to that, there is a specific database user associated to each client which can only read and write to this client's database schema. This database user is then used for all read and write operations triggered by employees of the client for reading, processing and visualizing any client data.
How do you handle data collection?
All data is collected and stored seperated. Data processing is limited to the minimal requirements necessary to fulfill our promised service offerings.