Security & privacy by design

WarnDesk handles sensitive workforce data, so protecting it is built into every layer — from the agent on the device to the encrypted connection and the isolated database behind your dashboard.

Encrypted in transit

Every connection between the agent, your dashboard and our servers is protected with HTTPS/TLS. The site is HTTPS-only with HSTS and secure, HTTP-only session cookies.

Encrypted sensitive data

Secrets like credential-vault entries and device enrolment keys are encrypted in the database. Passwords are never stored in plain text — they are one-way hashed with bcrypt.

Mandatory 2FA

Every dashboard account requires two-factor authentication (TOTP), backed by a strong password policy: minimum length plus upper- and lower-case, a number and a symbol.

Strict tenant isolation

Every request is scoped to the signed-in company. One customer can never see, query or reach another customer’s data — isolation is enforced on the server, not just the screen.

Role-based access control

Granular admin / manager / user roles (and separate platform roles) decide who can view screens, manage devices, see reports or change billing — enforced on both the interface and the API.

Signed, verified agent

The WarnDesk agent is code-signed and its integrity is verified before it runs. It is built with a least-privilege design and updates are delivered securely.

Audit logging & monitoring

Security-relevant events — sign-ins, IP addresses and administrative actions — are logged, and automatic crash/error monitoring flags problems fast.

Hardened hosting

WarnDesk runs on a hardened, access-controlled private server with regular updates, backups and periodic security review.

You own your data

Your company is the owner and controller of the monitoring data collected from your devices. WarnDesk processes it only to provide the service, on your instructions — we don’t sell it or use it for advertising. Data is separated per company, retained according to your plan, and removable on request. See our Privacy Policy for the full detail.

Transparent monitoring

Security and trust go together. WarnDesk can show an on-device notice — with your own company name — so employees always know monitoring is active, and monitoring can be limited to working hours and shifts. It’s oversight without secrecy. Learn more in our guide on monitoring computers legally and ethically.

Report a security issue

If you believe you’ve found a security vulnerability, we want to hear from you. Email support@warndesk.com and we’ll investigate promptly. Please give us reasonable time to fix an issue before disclosing it publicly.

Security FAQ

Is WarnDesk secure?

Yes. WarnDesk is built with security by design: encrypted connections (HTTPS/TLS), encryption of sensitive stored data, bcrypt-hashed passwords, mandatory two-factor authentication, strict per-company data isolation, role-based access control, a code-signed agent, audit logging and hardened hosting.

Is my company’s data kept separate from other companies?

Yes. WarnDesk is multi-tenant with strict isolation. Every request is scoped to your company on the server side, so no other customer can ever access your data.

Who owns the monitoring data?

You do. Your company is the owner and data controller of the monitoring data collected from your devices; WarnDesk processes it only to provide the service, on your instructions. You can read the details in our Privacy Policy.

How are passwords and secrets protected?

Account passwords are one-way hashed with bcrypt and never stored in plain text. Sensitive items such as stored credentials and device enrolment keys are encrypted in the database, and all traffic is encrypted with TLS.

Monitoring you can trust

Secure, transparent and built for Windows 10 & 11. Try every feature free.