DoLessWork · Security
Where your data lives, and who touches it.
Written to be forwarded to whoever reviews your vendors. It answers the questions a security review actually asks, including the ones where the answer is no.
Your data is stored in Oregon, United States (US West).
Which of us is responsible for what
You are the controller of your customers' data. We are a processor: we handle it only to run the service for you, and only in the ways your standing rules describe. If you are an outsourcing provider or an agency, that makes us a sub-processor to your own clients — the register below is what your contract with them will ask you to disclose.
We will sign your data processing agreement. Send it with your questionnaire to hello@mail.dolesswork.com and a person will complete both. We do not have a self-serve DPA to download yet.
Where the data is stored
All workspace data is hosted with Render in Oregon, United States (US West). Workspace data is stored on a persistent disk in that one region. It is not replicated to other regions, and there is no separate EU or Asia-Pacific instance today.
Said plainly because it matters to you and not to us: if your clients are in the EU or the UK, their data leaving your jurisdiction for the United States is a transfer you have to account for, and you should check it against your own obligations before you sign anything. We would rather you find that out on this page than after.
Sub-processors
The complete list. Each receives only what its feature needs, at the moment that feature runs — nothing is sent in bulk, and none of them are used for advertising.
- Render
- Hosting and data storage. Receives: All workspace data, on a persistent disk. Processed in Oregon, United States (US West).
- Anthropic
- Drafting replies and scoring enquiries. Receives: The text of the enquiry being answered, your standing rules, and your business profile — sent per draft, not in bulk. Processed in United States.
- Resend
- Sending the emails you approve, and invoice reminders. Receives: The recipient address and the message body, at the moment it is sent. Processed in United States.
- Vapi
- Answering the phone, when voice is switched on. Receives: Call audio and its transcript, for calls to your DoLessWork number. Processed in United States. Only if you ask for voice answering — it is an optional add-on and off by default.
If we ever add one, it appears here in the same change that adds it. Ask us to tell you when that happens and we will.
What we never hold
Often the faster half of a security review:
- Card numbers or bank details — there is no card-payment path in the product at all
- Passwords or API keys for your other systems — we never ask for them and there is nowhere to enter them
- Analytics, tracking pixels, or third-party advertising cookies — the only cookie is your session
- Open, click, or delivery tracking on any message — the product does not measure these at all
Access and controls
- Passwords are bcrypt-hashed; sessions are signed, httpOnly cookies over HTTPS.
- Roles decide what is reachable, not just what is visible — if a role cannot do something, the control is not rendered and the route refuses it as well.
- Every AI draft, every human approval and every send is recorded in an audit trail you can read and export yourself.
- Public signup is closed. Workspaces are provisioned by us, so there is no path for an uninvited account to exist alongside yours.
- You can export everything we hold as JSON in one click, at any time, without asking.
What the system will not do
These are enforced in code and asserted by our test suite, not promised in a policy:
- No drafted reply is ever sent without a person approving that specific message. There is no auto-send tier, at any price.
- Sensitive classes are never answered by a draft — contracts, compliance and security questions, payment and bank details, and disputes are held for a person.
- Nothing measures opens, clicks or deliveries. We do not have that data to give anyone, including ourselves.
- We do not send bulk cold outreach from the product, for you or for us.
- We do not sell your data or use your workspace content to train anything.
If something goes wrong
If we learn of a breach affecting your workspace we will notify you within 72 hours of becoming aware of it, with what we know at the time rather than waiting for a complete picture. Report a suspected vulnerability to hello@mail.dolesswork.com and a person will answer.
What we are not
You will ask for these in your first email, so here they are without being asked:
- SOC 2 — not audited
- ISO 27001 — not certified
- HIPAA — no Business Associate Agreement offered, which is why insurance-billing healthcare providers are turned away
- No third-party penetration test has been commissioned
- No 24/7 staffed security operations centre
We are a small and new company and none of the above is in progress. If a certification is a hard requirement for your clients, we are not the right vendor yet, and we would rather say that here than discover it together in week three.
Questions this page did not answer
Send your security questionnaire or DPA to hello@mail.dolesswork.com and a person completes it — a draft never answers a security or compliance question, which is the same rule the product applies to your own enquiries. See also our Privacy Policy and Terms of Service.