Information Security Policy
Share
This Information Security Policy describes how Worklittle, operated by Curastem, protects the confidentiality, integrity, and availability of information processed through worklittle.com, worklittle.com/business, api.worklittle.com, and related services.
Scope
This policy applies to Worklittle systems, infrastructure, employees, contractors, and service providers who access or process Worklittle data.
Security governance
Worklittle maintains security practices appropriate to the sensitivity of the data we process. We review controls regularly and update them as our services and threat landscape evolve.
Infrastructure
Production services run on modern cloud infrastructure with secrets kept out of source code.
Secrets and credentials are stored in managed secrets systems, not in application source.
Application data is stored in our production databases and object storage. Authentication is provided by a dedicated identity provider.
Encryption and transport security
All public web and API traffic is served over HTTPS with TLS.
Sensitive credentials and API keys are never transmitted in URLs or client-side logs.
Authentication and identity
User sign-in uses a managed authentication provider.
Platform and API access require authenticated sessions or scoped API keys.
Cross-site request protections apply to authenticated application routes.
Monitoring and incident response
Production errors and operational events are monitored.
Suspected security incidents are triaged promptly, contained, and remediated.
When required, Worklittle notifies affected users and relevant authorities in accordance with applicable law.
Third-party services
Worklittle uses vetted third-party providers for hosting, authentication, email, payments, and AI processing. Providers are selected based on security posture and contractual protections.
Questions
For security questions or to report a vulnerability, contact contact@worklittle.com.
Author

Worklittle