Security & privacy by design
WarnDesk handles sensitive workforce data, so protecting it is built into every layer — from the agent on the device to the encrypted connection and the isolated database behind your dashboard.
Encrypted in transit
Every connection between the agent, your dashboard and our servers is protected with HTTPS/TLS. The site is HTTPS-only with HSTS and secure, HTTP-only session cookies.
Encrypted sensitive data
Secrets like credential-vault entries and device enrolment keys are encrypted in the database. Passwords are never stored in plain text — they are one-way hashed with bcrypt.
Mandatory 2FA
Every dashboard account requires two-factor authentication (TOTP), backed by a strong password policy: minimum length plus upper- and lower-case, a number and a symbol.
Strict tenant isolation
Every request is scoped to the signed-in company. One customer can never see, query or reach another customer’s data — isolation is enforced on the server, not just the screen.
Role-based access control
Granular admin / manager / user roles (and separate platform roles) decide who can view screens, manage devices, see reports or change billing — enforced on both the interface and the API.
Signed, verified agent
The WarnDesk agent is code-signed and its integrity is verified before it runs. It is built with a least-privilege design and updates are delivered securely.
Audit logging & monitoring
Security-relevant events — sign-ins, IP addresses and administrative actions — are logged, and automatic crash/error monitoring flags problems fast.
Hardened hosting
WarnDesk runs on a hardened, access-controlled private server with regular updates, backups and periodic security review.
You own your data
Your company is the owner and controller of the monitoring data collected from your devices. WarnDesk processes it only to provide the service, on your instructions — we don’t sell it or use it for advertising. Data is separated per company, retained according to your plan, and removable on request. See our Privacy Policy for the full detail.
Transparent monitoring
Security and trust go together. WarnDesk can show an on-device notice — with your own company name — so employees always know monitoring is active, and monitoring can be limited to working hours and shifts. It’s oversight without secrecy. Learn more in our guide on monitoring computers legally and ethically.
Report a security issue
If you believe you’ve found a security vulnerability, we want to hear from you. Email support@warndesk.com and we’ll investigate promptly. Please give us reasonable time to fix an issue before disclosing it publicly.
Security FAQ
Is WarnDesk secure?
Yes. WarnDesk is built with security by design: encrypted connections (HTTPS/TLS), encryption of sensitive stored data, bcrypt-hashed passwords, mandatory two-factor authentication, strict per-company data isolation, role-based access control, a code-signed agent, audit logging and hardened hosting.
Is my company’s data kept separate from other companies?
Yes. WarnDesk is multi-tenant with strict isolation. Every request is scoped to your company on the server side, so no other customer can ever access your data.
Who owns the monitoring data?
You do. Your company is the owner and data controller of the monitoring data collected from your devices; WarnDesk processes it only to provide the service, on your instructions. You can read the details in our Privacy Policy.
How are passwords and secrets protected?
Account passwords are one-way hashed with bcrypt and never stored in plain text. Sensitive items such as stored credentials and device enrolment keys are encrypted in the database, and all traffic is encrypted with TLS.
Monitoring you can trust
Secure, transparent and built for Windows 10 & 11. Try every feature free.