Skip to content
UploadWerk
Tools FAQ Contact About
Trust

Security and Data Handling

Implemented safeguards, data boundaries and current limitations.

1. File and workflow safeguards

  • HTTPS, secure HTTP-only session cookies in production, CSRF protection, trusted-host checks and restrictive browser security headers.
  • Upload validation for allowed type, size, file signature, spreadsheet archive structure, table shape and formula-injection payloads.
  • Required malware scanning for public uploads.
  • Random internal workflow references, no public upload paths and no-store download responses.
  • Automatic deletion of temporary workflow state according to the configured 1 hour period.

2. Access and administration

  • Server-side authorization for administrator routes.
  • Separate administrator sign-in and multi-factor authentication in production.
  • Rate limits for uploads, sign-in, contact submissions and other sensitive actions.

3. Data minimization and monitoring

Operational events and processing trails are designed not to contain raw spreadsheet rows or employee, payroll, bank, address, email or national-identification values. They record technical workflow information, counts, status and request references.

Application and infrastructure logs support operational review. Optional external error monitoring is configured to remove request bodies, cookies and user details before transmission.

4. Current limitations

UploadWerk has not undergone ISO 27001 or SOC 2 certification, an independent security audit or a formal third-party penetration test.

Backup restoration, incident response and change review include operator-managed procedures. No guaranteed recovery time, 24/7 monitoring or independently audited control effectiveness is claimed.

Customers must assess whether the current safeguards meet their organization, customer and project requirements.

5. Security reporting

Report suspected security issues privately to uploadwerk@gmail.com. Do not include real customer data or perform destructive testing without written permission.

The detailed current measures are listed on the Technical and Organisational Measures page.

Version date: 2026-07-29

Back to Trust Center
Your temporary workflow will expire soon. Keep working to retain your current uploads and settings.
Trust Center