World ReadyWorld Ready
For Recruiters For Institutions Product Pricing Compare FAQ
Request a demo
← Legal disclosure · security overview

Security Overview.

  • Effective 1 September 2026
  • Version 1.0
  • World Ready Pte Ltd

Why this page reads differently to other vendors'. Most security pages are a list of controls with no indication of which ones are actually in place. This one tells you where we are, what we rely on our cloud provider for, and what we don't have yet. We'd rather you found the gaps here than in a questionnaire. That's the same policy as /no-claims/, applied to security.

Our Data Processing Terms incorporate this page by reference, so everything below is contractual: we will not materially reduce these measures during your subscription term.

contents
  1. ·The short version
  2. 1Access control and tenancy
  3. 2Our people
  4. 3Infrastructure
  5. 4Environments
  6. 5What we don't have yet
  7. 6Data handling
  8. 7Reporting a security issue
  9. 8Questions
Contents
  1. ·The short version
  2. 1Access control and tenancy
  3. 2Our people
  4. 3Infrastructure
  5. 4Environments
  6. 5What we don't have yet
  7. 6Data handling
  8. 7Reporting a security issue
  9. 8Questions

The short version

Certifications None. No SOC 2, no ISO 27001. We won't imply otherwise
Where your data sits See our Sub-processor list for hosting regions and every supplier's country
Who can see it Role-based, scoped per organisation, logged on every record
Breach notification to you Within 48 hours of confirmation — contractual, Schedule 1 §9
Report a vulnerability security@worldready.ai — we won't pursue good-faith researchers
Data deletion 30-day export window after termination, then deleted within 90 days

1.Access control and tenancy

These are the controls the product is built around, and they're documented in the platform's own help documentation.

  • Per-role permission matrix. Permissions are defined per role, not per person — roles as columns, permissions as rows. Administrators in your organisation control who holds which role.
  • Separate data scope. A user sees only the records their role and scope permit. Scope is a first-class concept in the platform, not an afterthought bolted onto a query.
  • Read-only audit history on records. Who changed what, and when. It cannot be edited by users, including administrators. This exists because our customers need it for their own ESOS and National Code record-keeping, not just because we like audit trails.
  • Least privilege for our own staff. Access to Customer Data is limited to personnel who need it to deliver the service, is role-based, is reviewed at least annually, and is revoked promptly on role change or departure.
  • Named accounts only. Credential sharing is prohibited by our Terms, because a shared login destroys the audit history's value.

2.Our people

  • Everyone with access to Customer Data is bound by written confidentiality obligations that survive the end of their engagement.
  • We carry out identity and reference verification before granting access.
  • We are a small team. That's a genuine trade-off, and we'd rather name it than let you discover it: fewer people means a smaller attack surface and no anonymous internal access, but it also means we do not have a dedicated security function, a 24/7 on-call rota, or separation of duties in the way a large vendor does. Our breach commitment in Schedule 1 §9 is set at 48 hours precisely because it is a figure we can hit every time with the team we actually have.
  • Third-party criminal-record screening: not currently carried out.
  • Formal recurring security-awareness training programme: not currently in place.

3.Infrastructure

  • The platform runs on Amazon Web Services. Regions are listed on our Sub-processor list.
  • Dedicated and customer-hosted deployments. Some customers run the platform inside their own AWS account or a dedicated environment. Where that applies to you, the hosting location, infrastructure controls and backup arrangements are those stated in your Order Form, and you retain control of the underlying account.
  • Connections are encrypted in transit. The website and the application are served over HTTPS only.
  • Encrypted at rest. The production database, the search index and document storage are encrypted at rest. The database also has deletion protection enabled.
  • Backups. Automated database backups are retained for 7 days, with point-in-time recovery to any moment inside that window. Restoration beyond 7 days is not possible — see section 5. Search-index snapshots are taken and held by AWS; restoring one requires an AWS Support request rather than being self-service.
  • We rely on our cloud provider's platform controls for physical security, hardware lifecycle, hypervisor isolation, network-level DDoS protection and storage durability. AWS publishes its own certifications; ours are separate from theirs, and we don't borrow them.

4.Environments

  • Production and non-production environments are separated.
  • Customer Data may be present in a non-production environment — for example a UAT tenant during implementation, a migration run, or a support investigation — where you have asked us to put it there. When it is, the same access controls and confidentiality obligations apply. We say this plainly because a blanket "no production data in test" claim would be untrue for a business that does paid data migrations.

5.What we don't have yet

Publishing this list is deliberate. Every item is either on the roadmap or a conscious decision to wait until we can do it properly.

Not in placePosition
SOC 2 Type II Not held. We will not begin the audit process until the underlying controls are documented well enough to pass honestly
ISO 27001 Not held
Independent penetration test Not yet commissioned. When one is, we'll publish that it happened and share the summary under NDA
Published uptime SLA We publish no figure until there's a public status history to back it. Committed service levels are agreed in contract
Formal written incident response runbook with a named owner In progress. The 48-hour notification commitment in Schedule 1 §9 applies regardless — it is contractual from the effective date, runbook or no runbook
Customer-managed encryption keys Not offered
Single sign-on / SAML Ask us — availability depends on your plan and deployment
Bug bounty programme No paid programme. We do accept and act on reports at security@worldready.ai
Long-term backup archives Not held. Database backups are retained 7 days with point-in-time recovery inside that window; there is nothing beyond it
Cross-region or cross-account backup copies None. A failure affecting our region has no out-of-region copy to fall back on
Version history on uploaded documents Not enabled in our primary document store. An overwritten or deleted document there is not recoverable
Automatic deletion of AI conversation history Being implemented, not yet in force — see section 6

If a row above changes, this page changes the same week. If you're evaluating us and one of these is a blocker, tell us — knowing which gap costs us a deal is how we prioritise closing it.

6.Data handling

  • Your data is yours. We process it only on your instructions, under Schedule 1 of our Terms.
  • We do not use Customer Data to train, fine-tune, evaluate or benchmark any machine-learning model. Where you use AI features, the AI provider processes your data to return output to your tenant and is contractually prohibited from training on it.
  • AI conversation history. Where your team uses the Edi assistant, conversation history is stored in our own database. An automatic 24-hour deletion policy is being implemented and is not yet in force — until it is, conversation history is retained. We would rather tell you that than publish the policy we intend to have. The application records a conversation refers to are unaffected; they remain governed by your own retention settings.
  • Connected mailboxes. Where a user connects a Microsoft 365 or Google mailbox, we store only metadata — subject, sender, recipients, a short preview and dates. Message bodies and attachment contents are not retained. They are fetched from your mail provider at the moment a user opens them. There is no email archive in production.
  • Sensitive data. We know the platform holds passports, financial evidence, nationality, health-insurance records and, sometimes, character declarations — including for people under 18. Annex A of our Data Processing Terms declares all of it explicitly, which is unusual and intentional: a processor that hasn't written down what it holds hasn't thought about protecting it.
  • Deletion. 30-day export window after termination, then deletion within 90 days, except where law requires retention. We'll certify deletion in writing on request.

7.Reporting a security issue

Email security@worldready.ai with enough detail to reproduce the issue.

  • We will acknowledge and keep you updated.
  • We will not pursue legal action against researchers acting in good faith who use this channel, avoid privacy violations and service degradation, and give us reasonable time to fix the issue before disclosing.
  • Our Terms prohibit unauthorised scanning and load-testing — reporting through this channel is expressly carved out of that prohibition.

8.Questions

Security questionnaires and DPA signature requests: privacy@worldready.ai. We'll answer the questionnaire with the same candour as this page, which occasionally costs us a deal and has never cost us a customer's trust.

World ReadyWorld Ready
Product For providers For recruiters Pricing Compare FAQ Privacy Terms Legal What we won't claim Request a demo hello@worldready.ai

World Ready Pte Ltd (UEN 202406764D) · Singapore. Every feature described on this site traces to the platform's help documentation; nothing here is aspirational. Pricing shown is the proposed subscription model.