> ## Documentation Index
> Fetch the complete documentation index at: https://help.gowindmill.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and Compliance

> Windmill's security measures, compliance certifications, access controls, audit logging, and the practices in place to protect customer data and infrastructure.

Windmill maintains enterprise-grade security measures and compliance certifications to protect your organization's data.

## SOC 2 Type 2 compliance

**Windmill is SOC 2 Type 2 Compliant.** This certification demonstrates our commitment to maintaining high standards for security, availability, and confidentiality.

The full SOC 2 report is available upon request—reach out to [support@gowindmill.com](mailto:support@gowindmill.com) to receive a copy.

<Info>
  SOC 2 Type 2 certification means an independent auditor has verified our
  security controls over an extended period, not just at a single point in time.
</Info>

## Security measures

**Encryption at rest**
All data stored in Windmill is encrypted at rest. This helps protect sensitive data, including employee records, feedback, and activity data from your connected systems.

**Encryption in transit**
All data transmitted between Windmill and your browser, as well as between Windmill and integrated services, is encrypted using industry-standard TLS protocols.

**Strict permissions enforcement**
Windmill checks workspace roles, org-chart scope, feature privacy, delegation, and applicable source permissions. Private source content does not become public when you connect it to Windmill. Windmill uses feature permissions for company-level activity and usage data.

**Cookie policy**
Windmill has a cookie policy in place to manage how our site tracks and stores data. You can review our full cookie policy on our website.

## Admin access and permissions

**Integration management**
Admins, HR Admins, and Integration Managers can create or manage company integrations in Windmill. This ensures centralized control over which systems are connected and what data is accessible.

**Required permissions by integration**
Each connected system has its own authorization requirements. Review the setup page for the integration before you connect it. See [Integrations](/integrations/integrations) for the available integration pages.

**HRIS**

* **BambooHR** - Bamboo Administrator role
* **ADP** - HR Admin or Super User
* **Paylocity** - Company administrator
* **Gusto** - Full Access administrator role
* **Justworks** - Admin role
* **Rippling** - Admin access

**Support tools**

* **Front** - Company administrator
* **Zendesk** - Administrator or Account Owner role

**CRM**

* **Salesforce** - Administrator role and your Salesforce Instance URL
* **HubSpot** - Admin role and your HubSpot Instance URL

**Project management**

* **Jira** - No explicit permission required, just a Jira account
* **Linear** - Administrator role
* **Asana** - Administrator role
* **GitHub** - Owner or Manager role
* **Notion** - Notion admin

**Meetings and communications**

* **Google Workspace** - Must be a Google Workspace Admin
* **Zoom** - Zoom account owner
* **Slack** - Ability to connect Slack to third-party applications and install Slack apps
* **Roam** - Administrator role

<Tip>
  If you're unsure whether you have the right permissions, contact your IT team
  or system administrator before attempting to connect an integration.
</Tip>

## Roles and access

Windmill has Admin, HR Admin, Integration Manager, Data Analyst, and Team Member roles. Roles control workspace capabilities. The org chart, delegation, source permissions, and feature privacy rules also affect content visibility.

See [Permissions and Access](/permissions-and-access) for the current capability matrix and access model.

## Additional resources

For more information about security and compliance:

* Visit our [Trust Center](https://app.drata.com/trust/7bd6416b-c1ac-4c6c-afb4-a015fe83db6b)
* Review our [Privacy Policy](https://gowindmill.com/p/privacy-policy)
* Request our SOC 2 report at [support@gowindmill.com](mailto:support@gowindmill.com)

## FAQs

<AccordionGroup>
  <Accordion title="What version of encryption is used for data at rest?">
    Windmill uses **AES-256 encryption** for all data at rest. This encryption
    is applied to all database instances, cache volumes, and automated backups.
    All encryption keys are managed through AWS Key Management Service (KMS).
  </Accordion>

  <Accordion title="What version of encryption is used for data in transit?">
    All data transmitted to and from Windmill is encrypted using **TLS 1.2 or
    higher**. This includes all external communications (such as your browser
    and API calls to integrated services) and all internal service and
    infrastructure communication.
  </Accordion>

  <Accordion title="Where is Windmill's data hosted?">
    Windmill's infrastructure is hosted in **Amazon Web Services (AWS)**
    datacenters in the United States.
  </Accordion>

  <Accordion title="Does Windmill undergo regular security testing?">
    Windmill undergoes regular security assessments including: - **Annual SOC 2
    Type 2 audits** by independent third-party auditors - **Automated
    vulnerability scanning** of our application and infrastructure -
    **Penetration testing** conducted by external security firms - **Code
    security reviews** as a core part of our SDLC. Results from these
    assessments inform our security roadmap and continuous improvement efforts.
  </Accordion>

  <Accordion title="Does Windmill publish a Section 508 or WCAG conformance statement?">
    Windmill's help center does not currently list a specific accessibility regulation or conformance standard such as Section 508, WCAG 2.1 or 2.2, ADA, or a VPAT. For a formal accessibility statement, VPAT, or WCAG/Section 508 confirmation, contact [support@gowindmill.com](mailto:support@gowindmill.com).
  </Accordion>
</AccordionGroup>
