Introduction
Security is shared work. This Policy explains how to report a vulnerability, the safeguards used for Reva Labs-operated services, and what you control when Worktable runs locally, on your own infrastructure, or in Worktable Cloud.
Worktable is local-first. A local workspace is a folder you own. Self-hosted Worktable runs on infrastructure you choose. Worktable Cloud adds a hosted identity, gateway, control plane, and dedicated workspace runtime operated for you.
Reporting a security issue
If you believe you found a vulnerability in Worktable or Reva Labs-operated infrastructure, email security@worktable.dev. Do not send passwords, API keys, access tokens, private keys, or unnecessary personal information.
Please include what you can:
- a clear description and the potential impact;
- the affected version, URL, endpoint, or component;
- reproduction steps or a minimal proof of concept;
- sanitized logs, screenshots, or request and response details; and
- how you would like us to contact or credit you.
We will acknowledge useful reports as soon as reasonably possible, investigate them, keep you informed when we have material progress, and coordinate disclosure after a fix is available. Resolution time depends on severity, complexity, and third-party dependencies.
Good-faith research and safe harbor
We support good-faith security research. If you make a genuine effort to follow this Policy, avoid harm, respect privacy, and report the issue promptly, we will treat your research as authorized and will not pursue legal action for accidental, good-faith violations of this Policy.
To stay within this safe harbor:
- test only accounts, data, and systems you own or have explicit permission to test;
- stop and report immediately if you encounter another person’s data or production secrets;
- access only the minimum information needed to demonstrate the issue;
- do not disrupt availability, degrade performance, delete data, or alter another user’s workspace;
- do not use denial of service, social engineering, phishing, physical attacks, or automated scanning that creates material load;
- do not test third-party providers or infrastructure outside Reva Labs’ control; and
- give us a reasonable opportunity to investigate and fix the issue before public disclosure.
This safe harbor does not authorize unlawful activity or activity outside the scope of this Policy. Worktable does not currently operate a bug bounty or promise financial rewards.
Our security practices
We use a combination of organizational and technical safeguards to protect Worktable Cloud. Our practices include:
- Access controls. We separate human and agent access and apply scoped, revocable permissions where appropriate.
- Workspace isolation. Hosted workspaces are isolated to reduce the risk of unauthorized access across workspaces.
- Layered protection. Requests are validated at multiple points, and access is limited according to identity and authorization.
- Credential and transport protection. We protect Worktable-managed credentials and use HTTPS for public Worktable Cloud traffic.
- Data minimization. We limit operational logging and design it to avoid workspace content, secrets, and payment details.
No system is completely secure. These controls reduce risk but cannot guarantee that Worktable will never contain a vulnerability or experience unauthorized access.
Local and self-hosted security
Local Worktable binds to your machine by default and does not require an account. When you make Worktable reachable from another device, the web app requires an owner password and agents require scoped tokens. Worktable refuses to enter the supported reachable posture without the required owner protection.
Self-hosted operators are responsible for their host, network, backups, TLS termination, updates, and access policy. Worktable serves plain HTTP locally; use a trusted HTTPS tunnel or reverse proxy before exposing it across a network.
Workspace files are portable and may contain sensitive information. Protect the folder, exports, backups, and any repository where you place them.
Your responsibilities
You can reduce risk by:
- keeping Worktable, your device, and connected tools current;
- protecting your account, provider, repository, and infrastructure credentials;
- using multi-factor authentication where it is available;
- granting agents only the permissions they need;
- reviewing commands, generated content, code, and file changes before applying them;
- revoking lost, compromised, or unused devices and agent connections; and
- keeping exports or backups appropriate to the value of your work.
Incidents, updates, and contact
We investigate suspected incidents, contain them, work with affected providers, preserve necessary evidence, and restore safe operation. When a privacy breach creates a real risk of significant harm, we report it and notify affected people as required by Canadian law. We keep a record of personal-information breaches for at least two years.
We may update this Policy as Worktable, our infrastructure, or our security practices change. Material changes to the reporting process or safe-harbor terms apply prospectively.
Security reports: security@worktable.dev
Legal and privacy questions: legal@worktable.dev
an Ontario-registered business