WorkerKit Security

How we protect what you connect, and the parts of that only you can do. A description of practice, not a contract.

Last Updated: August 3, 2026
Version: 1.0

This page describes how WorkerKit protects the accounts and data you connect to it. It is the page referenced by Section 2.3 and Section 7 of the WorkerKit Privacy Policy.

This page is a description of our current practices, not a contract. Our binding commitments are in the Terms of Service, the Privacy Policy, and, for customers who sign one, the Data Processing Agreement. We update this page as our practices change, and nothing here creates a warranty or guarantee. Capitalized terms have the meaning given in the Terms of Service.

We do not promise that WorkerKit is secure. We work hard at it, everything described below is real, and none of it is a guarantee. No system of this kind can be made safe against every threat, and we would rather say so here than let you infer a promise we cannot keep. Security measures reduce risk. They do not remove it. If that is not a risk you are willing to take with a particular account, do not connect that account. If it is not a risk you are willing to take at all, do not use WorkerKit. Sections 20 and 21 of the Terms of Service say this in the language that binds, and nothing on this page overrides them or adds to them.

1. What You Are Actually Trusting Us With

We would rather state the risk plainly than lead with reassurance.

WorkerKit is not a chatbot. A Worker holds live authorization to accounts you already own, and it takes actions in them: it reads mail, writes records, moves files, sends messages, and deletes things. That means two categories of data matter here, and they are not the same:

The controls below are organized around that split, because losing a Credential and logging a paragraph are different failures with different consequences.


2. Credentials


3. The Access You Grant Is the Access It Has

The strongest security control on this platform is not one of ours. It is how narrowly you grant access in the first place, and the product is built so you can grant very little.

Grant the narrowest access that does the job. A Worker that files invoices needs the Invoices folder, not your Drive.

These are controls you configure, and like every control they are tools rather than guarantees. We do not warrant that any of them will prevent a particular disclosure, action, or loss, and none of them is a substitute for scoping access narrowly, testing before you rely on a Worker, and watching what it does. Section 6.4 and Section 20(i) of the Terms of Service are the binding statement of that.


4. Content During and After a Run

We do not train generative models on your Inputs, Outputs, Connected Account data, or Operational Metadata. Evaluation is measurement, not training.


5. Platform and Operations

Our current technical and organizational measures include:

This list describes what we do. It is not a commitment to a security standard, a certification, or an outcome, and it may change as our systems change. No method of transmission over the internet and no method of electronic storage is completely secure, and we do not guarantee absolute security. See the statement at the top of this page and Section 20 of the Terms of Service.


6. Kits Are Not Reviewed

This belongs on a security page because it is the thing most likely to be assumed wrong.

WorkerKit does not review, audit, verify, certify, or endorse the Kits in the directory. Kits are third-party content, provided as is. Install counts, stars, success rates, and rankings are measurements of observed activity, not a review, and a Kit with favorable numbers is still an unreviewed third-party Kit.

Before you install one:

Report a Kit that misdescribes itself, requests access it does not need, or behaves maliciously to security@workerkit.ai. Sections 4 and 5 of the Terms of Service and Section 12 of the Acceptable Use Policy set the rules Kit Creators are held to.


7. Integrations You Add Are Not Reviewed Either

You can connect third-party services we never selected or onboarded: MCP servers, gateways, webhooks, endpoints, and other integrations you or your organization supply. Doing that is entirely your call, and it is the fastest way to widen what a Worker can reach.

We do not review, test, verify, or endorse any of them, and we cannot see what their operators do with the data a Worker sends. Two things about them are worth understanding before you connect one:

Connect only what you trust, give it the least you can, and watch what it does with the first runs. Section 6.9 of the Terms of Service is the binding version of this section.


8. Incidents

If we become aware of a personal data breach affecting your personal data, we notify you and any applicable regulator as required by law, and within the timeframes in the Data Processing Agreement for customers who have one.

Tell us immediately at security@workerkit.ai if you believe your WorkerKit account or a Connected Account has been compromised. If a Connected Account is involved, also revoke WorkerKit's access at the App Provider directly. That takes effect immediately and does not depend on us.


9. Reporting a Vulnerability

Send security reports to security@workerkit.ai. Include what you found, how to reproduce it, and what an attacker could do with it.

Section 12 of the Terms of Service governs security research. In short: test only accounts and data you own or have written permission to test, do not access, modify, or exfiltrate anyone else's data, do not degrade the Service, do not use a finding for any purpose beyond demonstrating it, and give us reasonable time to fix an issue before disclosing it. Research conducted within those limits is authorized, and we will not pursue you for it.

We acknowledge reports and work them by severity. We do not run a paid bug bounty program at this time.


10. Your Side of It

Some of this is only yours to do:


11. Compliance Posture

Stated plainly so you do not have to infer it from what is missing.


12. Changes to This Page

We update this page as our practices change, and we do not treat it as amendable-only-by-notice the way the Terms and the Privacy Policy are. If a change reduces a protection described here in a way that materially affects you, the Privacy Policy's notice provisions in Section 1.4 apply.


13. Contact

WorkerKit
10900 Stonelake Blvd
Austin, TX 78759, United States