Coding agent documentation index Fetch the complete documentation index at: https://docs.worklittle.com/docs-agent-manifest.json Use this file to discover all available pages before exploring further.

Compliance and security

How Worklittle protects accounts, company data, and everyday access.

Worklittle is built so people and companies can trust what they put in the product. This page is the plain-language version of how we think about security and responsible use.

What we care about protecting

- Accounts and sign-in, so only you can open your workspace - Job seeker data, such as resumes, chats, and applications - Company data on Worklittle Business, such as candidates, employees, documents, surveys, and billing - API keys and payments, so developers and finance stays locked down to the right people

How access is kept tight inside a company

On Worklittle Business, every teammate has a role. The role is not just a label - it changes which pages appear and what chat is allowed to know.

- Can chat teammates get a personal experience. Hiring pages stay hidden, and chat will not surface pipeline or other people's private records. - Higher roles unlock more of the workspace only as needed. - Billing, usage, and spend limits stay with Full access and Owner.

That least-access model is one of the main ways company information stays private day to day. Full detail: Roles and permissions.

Sign-in and keys

- Sign-in uses Google, a one-time email code, or an optional password you set. See Trouble signing in. - Sessions and API keys are required for protected actions. - API keys inherit what their creator's role can do, so a limited teammate cannot mint a key that outranks them. - Public traffic to the site and API runs over HTTPS.

Infrastructure and monitoring

- Production services run on modern cloud infrastructure with secrets kept out of source code. - Operational issues are monitored so problems can be spotted and fixed quickly. - Suspected security incidents are triaged, contained, and remediated. When the law requires it, affected people are notified.

For the formal write-up, read the Information security policy. Worklittle does not advertise HIPAA or FedRAMP badges in Help. See Is Worklittle HIPAA or FedRAMP certified?.

Your part as a customer

Security is shared. A few habits go a long way:

- Invite people with the smallest role that still works for their job. - Remove teammates when they leave. - Keep API keys in safe places and rotate them if someone who had access leaves. - Do not paste secrets, government IDs, or card numbers into chat. - Verify a work email before publishing jobs. See Verify a work email.

Policies and where to ask

| Document | What it covers |
| --- | --- |
| [Privacy policy](https://worklittle.com/privacy) | What we collect and why |
| [Terms of service](https://worklittle.com/terms-of-use) | The agreement for using Worklittle |
| [Information security policy](https://worklittle.com/information-security-policy) | How we protect systems and data |
| [Access controls policy](https://worklittle.com/access-controls-policy) | How access is granted and removed |
| [Data retention and disposal](https://worklittle.com/data-retention-and-disposal-policy) | How long data is kept |

Vulnerability reports: [contact@worklittle.com](mailto:contact@worklittle.com). Everyday product help: Contact support. Which inbox: Who do I email?.