For the complete documentation index, see llms.txt. This page is also available as Markdown.

Compliance FAQs

This document addresses frequently asked questions about We360.ai's compliance posture, security controls, data handling practices, and regulatory alignment.


1. General Security & Compliance Posture

Q: What certifications and compliance standards does We360.ai hold?

We360.ai maintains the following certifications and compliance attestations:

Certification / Standard
Status
Details

ISO/IEC 27001:2022

Certified

Information Security Management System (ISMS). Independently certified.

SOC 2 Type II

Attested

Covers Security, Confidentiality, and Availability trust service criteria. Audit period: April–October 2024. Clean opinion issued. Recertification is conducted annually.

SOC 2 Type I

Attested

Precursor to Type II. Completed 2023.

GDPR

Audited & Compliant

Independent audit confirmed adequately designed controls across all GDPR requirements.

HIPAA

Assessed & Compliant

Assessed against NIST SP 800-66 Rev 2. All Administrative, Physical, Technical, and Organizational safeguards found compliant.

VAPT

Certified

Annual Vulnerability Assessment & Penetration Testing. Application certified free from OWASP Top 10 and other known vulnerabilities.

Q: Does We360.ai undergo regular security testing?

Yes. We360.ai conducts:

  • Annual VAPT — Web application penetration testing against OWASP Top 10 and other known vulnerability classes. Retesting is performed to confirm remediation of any findings.

  • Static Application Security Testing (SAST) — Automated scanning of the codebase for known vulnerabilities in dependencies and libraries.

  • Periodic security audits — Independent third-party assessments across ISO 27001, SOC 2, GDPR, and HIPAA frameworks.

Q: Does We360.ai have a formal Information Security Management System (ISMS)?

Yes. We360.ai operates a formal ISMS aligned with ISO/IEC 27001:2022. The ISMS encompasses:

  • Documented security policies and procedures (32+ active policies)

  • Defined information security roles and responsibilities (CISO, Privacy Officer, Information Security Group)

  • Risk management procedures with regular risk assessments

  • Internal audit and continual improvement processes

  • Management review meetings for ISMS oversight

Q: Can We360.ai provide compliance documentation for our vendor assessment?

Yes. We360.ai can furnish the following upon request (subject to NDA where applicable):

  • ISO 27001:2022 certificate and Statement of Applicability

  • SOC 2 Type II report

  • GDPR compliance audit report

  • HIPAA assessment report

  • VAPT certificate and web application security report

  • Individual security policies (e.g., Access Control, Encryption, Incident Management)

  • Architecture and data flow diagrams

  • Completed security questionnaires (We360.ai has experience completing assessments for financial services, insurance, and enterprise clients)

Q: Can customers conduct their own penetration testing or security assessments?

Yes. We360.ai supports customer-initiated security assessments against their We360.ai environment, subject to the following process and rules of engagement.

Requesting a Test:

  1. Notification — Customers must submit a formal testing request to security@we360.ai at least 14 business days prior to the anticipated start date.

  2. Required details — The request must include:

    • Proposed testing dates and duration

    • Originating IP addresses of all testers

    • List of automated tools that will be used

    • Contact information for the lead tester (name, email, phone)

  3. Approval — Testing may only commence after receiving written authorization and a finalized scoping agreement from the We360.ai Information Security team. Unauthorized testing will be treated as a security incident.

Rules of Engagement — Prohibited Activities:

Prohibited Activity
Description

No Denial of Service (DoS/DDoS)

Volumetric attacks, network stress testing, or any attempt to exhaust system resources (e.g., brute-forcing login portals at high velocity) are strictly prohibited.

No Infrastructure Scanning

Network-level vulnerability scanning or exploitation targeting the underlying cloud infrastructure (e.g., Kubernetes nodes, AWS/GCP/Azure resources, managed databases) is not permitted. Testing must be limited to the We360.ai application layer.

No Cross-Tenant Attacks

Any active attempt to access, view, or modify data belonging to other We360.ai customers is prohibited. Testing for horizontal privilege escalation is permitted, but testers must immediately halt and report if they successfully access cross-tenant data.

Reporting: Upon completion, testers are expected to share a summary of findings with the We360.ai Information Security team at security@we360.ai. We360.ai commits to acknowledging findings within 48 hours and providing a remediation timeline based on severity.

Q: Does We360.ai have a vulnerability disclosure or bug bounty program?

We360.ai maintains a responsible vulnerability disclosure policy. Security researchers and customers who discover potential vulnerabilities are encouraged to report them to security@we360.ai. Reports are triaged promptly, and We360.ai commits to acknowledging receipt within 48 hours and providing a remediation timeline based on severity.


2. Data Privacy — GDPR, DPDP Act & CCPA

Q: Is We360.ai GDPR compliant?

Yes. We360.ai has undergone an independent GDPR compliance audit and has been found to have adequately designed controls to meet GDPR requirements in all material respects. Key GDPR measures include:

  • Lawful basis for processing — Processing is carried out under a valid legal basis (contract performance, legitimate interest, or consent as applicable).

  • Data Processing Addendum (DPA) — Available for all customers subject to GDPR, incorporating Standard Contractual Clauses (Commission Decision 2021/914) for international data transfers.

  • EU Representative — A GDPR Representative has been formally appointed in the EU to serve as a point of contact for data protection authorities and data subjects.

  • Data subject rights — Full support for access, rectification, erasure, portability, restriction of processing, objection, and withdrawal of consent. Requests are addressed within one month under GDPR, and as soon as reasonably practicable under other applicable regulations.

  • Data Protection Officer (DPO) — Reachable at dpo@we360.ai.

  • Data minimization — Only data necessary for the specified purpose is collected and retained.

  • Privacy by design — Built-in privacy controls including screenshot blurring, configurable tracking scope, and shift-based monitoring.

  • Processor breach notification SLA — As a Data Processor, We360.ai commits to notifying the customer (the Data Controller) of any confirmed personal data breach within 24 hours of becoming aware of the breach. This gives the Controller sufficient time to assess the incident and fulfill its own regulatory obligation to notify the supervisory authority within 72 hours under GDPR Article 33. The notification includes the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach. See Section 8 for full incident management details.

Q: How does We360.ai comply with India's Digital Personal Data Protection (DPDP) Act 2023?

We360.ai aligns with the DPDP Act 2023, including:

  • Clear purpose limitation and consent mechanisms for personal data processing

  • Provision for data principal rights (access, correction, erasure)

  • Designated Grievance Officer for data protection queries

  • Data stored in India, supporting data localization requirements

  • Documented retention and deletion policies to ensure data is not retained beyond its lawful purpose

Q: Does We360.ai support CCPA requirements?

Yes. We360.ai supports CCPA requirements through:

  • Transparency about data collection and usage practices via the Privacy Policy

  • Mechanisms for consumers to request access to, deletion of, and information about their personal data

  • We360.ai does not sell personal data to third parties

Q: What is We360.ai's data retention policy?

Data retention is governed by the Data and Record Retention and Deletion Policy. Key retention periods:

Data Category
Retention Period

Client/customer data

Duration of contract + 3 months

End-user monitoring data

1 year post-termination of services

Database backups

1 month (rolling)

Trial account data

Deleted within 1 month of trial expiry

Financial/billing records

7+ years (statutory requirement)

Upon expiry of the retention period, data is securely deleted or irreversibly anonymized. Customers may also request data deletion at any time, subject to contractual and legal obligations.

Q: Does We360.ai sell or share personal data with third parties?

No. We360.ai does not sell, rent, or commercially exploit customer or end-user data. Data is shared with third-party subprocessors only as necessary for service delivery (e.g., cloud hosting, payment processing), under strict confidentiality obligations and data processing agreements.


3. HIPAA

Q: Is We360.ai HIPAA compliant?

Yes. We360.ai has been assessed against NIST SP 800-66 Rev 2 and found compliant across all HIPAA safeguard categories:

  • Administrative Safeguards — Security management process, workforce security, information access management, security awareness and training, security incident procedures, contingency planning, evaluation

  • Physical Safeguards — Facility access controls, workstation use and security, device and media controls

  • Technical Safeguards — Access controls, audit controls, integrity controls, person or entity authentication, transmission security

  • Organizational Requirements — Business associate contracts, policies and procedures

  • Documentation Requirements — Required documentation and record retention

Q: Does We360.ai offer a Business Associate Agreement (BAA)?

Yes. We360.ai offers a Business Associate Agreement for customers whose use of the platform may result in incidental exposure to Protected Health Information (PHI).

Important clarification: We360.ai is a workforce analytics platform — it is not designed to purposefully collect, store, or process PHI. However, in certain environments (e.g., monitoring a telehealth worker's screen, or employees who handle electronic health records), screenshots or screen recordings may incidentally capture PHI visible on-screen. The BAA exists to provide contractual coverage for this incidental exposure, not to authorize We360.ai as a system for purposeful PHI processing.

Q: How does We360.ai minimize incidental PHI capture?

We360.ai is designed to minimize the risk of incidental PHI exposure through the following controls:

  • Screenshot Blur Engine — Automatically masks and blurs sensitive on-screen content in captured screenshots, including text fields, personal communications, financial data, and authentication fields. For healthcare environments, the Blur Engine significantly reduces the risk of readable PHI appearing in screenshots.

  • Screenshot frequency control — Administrators can reduce screenshot frequency or disable screenshots entirely for users who regularly handle PHI.

  • Screen recording toggle — Screen recording is off by default and must be explicitly enabled. Organizations monitoring healthcare workers should carefully evaluate whether screen recording is necessary and proportionate.

  • Shift-based tracking — Limits monitoring to designated work hours, reducing the window of potential PHI exposure.

  • Do Not Track list — Employees who routinely handle high volumes of PHI (e.g., clinical staff) can be excluded from screenshot and screen recording capture entirely while still being tracked for time and attendance.

  • Data retention controls — Screenshots that may contain incidental PHI are subject to the organization's configured retention period and are automatically deleted upon expiry.

Recommendation: Organizations in healthcare or telehealth should enable the Blur Engine, minimize screenshot frequency for clinical staff, and conduct a risk assessment to determine the appropriate monitoring scope for employees who handle PHI. The BAA should be executed before deployment in any environment where incidental PHI exposure is possible.

Q: How does We360.ai protect Protected Health Information (PHI)?

We360.ai implements multiple layers of protection for any PHI that may be incidentally captured:

  • HIPAA Internal Privacy Policy — Governs the use, disclosure, and protection of PHI, enforcing minimum necessary standards.

  • PHI De-identification Policy — Documented procedures for anonymizing health data when de-identified data is sufficient for the intended purpose.

  • Guidelines on Use and Disclosure of PHI — Operational guidelines covering permissible uses and disclosures, individual rights (access, amendment, accounting of disclosures), and administrative/physical/technical safeguards.

  • Encryption — PHI is encrypted both in transit (TLS) and at rest (industry-standard encryption algorithms).

  • Access controls — Role-based access with least-privilege principles; MFA for privileged access.

  • Breach notification — Documented HIPAA Breach Notification Policy aligned with regulatory timelines.


4. Data Collection & What Is NOT Collected

Q: What data does the We360.ai agent collect?

The We360.ai agent captures workforce productivity data at per-second granularity. The data collected includes:

Device Metadata:

  • Computer name and timezone

  • Operating system and domain information

  • Network identifier (hashed), private and public IP addresses

User Activity Data:

  • Active application names and window titles

  • URLs visited in browsers

  • Duration of activity per application/URL

  • Mouse click and keystroke frequency counts (aggregate counts only)

  • Screenshots of the active window (at a configurable frequency)

  • Screen recordings (if enabled by the organization)

Attendance & Location Data:

  • Login/logout timestamps, break patterns

  • GPS coordinates from the mobile app (for field workforce tracking, if enabled)

All data collection is configurable by the organization's administrators, allowing fine-grained control over what is captured.

Q: What does We360.ai NOT collect?

⚠️ IMPORTANT — Definitive Data Collection Boundaries

The following restrictions are absolute, apply to all deployment modes (Standard and Stealth), all platforms (Windows, macOS, Linux, mobile), and all hosting models (cloud, on-premise, BYOC). They are enforced by design and cannot be overridden by configuration. All other sections of this document that reference these boundaries defer to this section as the authoritative source.

We360.ai explicitly does NOT collect — and is architecturally incapable of collecting — the following:

  • ❌ Individual keystrokes (No Keylogging) — Only aggregate keystroke frequency counts are captured (e.g., keystrokes per minute as an activity indicator). Actual key presses, typed text, passwords, form inputs, chat messages, or any content entered by the user are never recorded, transmitted, or stored. The We360.ai agent does not contain a keylogger and has no mechanism to capture individual keystrokes.

  • ❌ Webcam or camera feeds — The platform never accesses device cameras or captures any video of the user. No webcam permissions are requested or used.

  • ❌ Audio or microphone dataNo audio recording is performed, ever. The platform does not access or request microphone permissions.

  • ❌ Personal file contents — File contents on the user's device are not accessed, read, or transmitted. The agent tracks application and window metadata only.

Q: Can organizations control what data is collected?

Yes. We360.ai provides extensive configurability:

  • Screenshot frequency — Adjustable from 2 per hour to 60 per hour, or disabled entirely.

  • Screenshot blurring (Blur Engine) — Automatic blurring/masking of sensitive on-screen content to prevent exposure of personal communications, financial details, or authentication fields.

  • URL and app tracking — Can be scoped or restricted via productivity rules and URL blocklists.

  • Shift-based tracking — Monitoring can be restricted to designated work hours and authorized environments only.

  • Screen recording — Optional; must be explicitly enabled.

  • Field/GPS tracking — Optional; applies only to the mobile app and must be enabled.

Q: Can employees see their own data?

Yes. In Standard mode, employees have access to their own productivity analytics, enabling self-assessment and improvement. This supports transparency and aligns with data protection principles around data subject access.


5. Encryption & Data Protection

Q: How is data encrypted in transit?

All data transmitted between the We360.ai agent and backend infrastructure is encrypted using:

  • HTTPS/TLS — All REST API communication uses TLS encryption over TCP port 443.

  • WSS (WebSocket Secure) — Real-time data streaming uses encrypted WebSocket connections.

  • No unencrypted channels — The platform does not transmit data over HTTP or any unencrypted protocol.

Q: How is data encrypted at rest?

Data at rest is protected using industry-standard encryption:

  • Database encryption — All databases (PostgreSQL, ClickHouse) use encryption at rest with platform-managed keys.

  • Object storage encryption — Screenshots, recordings, and backups stored in cloud object storage are encrypted.

  • Encryption standards — AES-256 encryption for data at rest, with symmetric keys of at least 128 bits and asymmetric keys of at least 2048 bits.

  • Key management — Encryption keys are managed through the cloud provider's key management services, with access restricted to authorized personnel.

Q: How is data handled when the agent is offline?

We360.ai uses an offline-first architecture:

  • Activity data is stored locally on the user's device in an encrypted local database when connectivity is unavailable.

  • Data is automatically synced to the server over encrypted HTTPS once connectivity is restored.

  • Local data is cleared after the server confirms receipt.

  • This ensures continuous, uninterrupted tracking regardless of internet stability.


6. Infrastructure, Hosting & Data Residency

Q: Where is We360.ai data hosted?

We360.ai uses an isolated cell-based architecture. Each cell is a fully independent deployment — with its own compute, database, and storage layers — ensuring complete data isolation between regions. Currently available cells:

Cell
Region

India

Default cell for all customers. Data is stored and processed entirely within India, supporting data localization requirements.

United States

Isolated US cell for customers requiring data residency within the United States.

Additional cells can be provisioned in other regions based on customer requirements.

Q: Does We360.ai support data residency requirements?

Yes. For cloud-hosted deployments, data is stored in India by default. For organizations with specific data residency or sovereignty requirements (e.g., EU, Middle East, or other jurisdictions), We360.ai offers:

  • We360.ai Managed Cloud — We360.ai hosts and manages the platform in a region of the customer's choice, removing the operational burden while meeting data residency requirements.

  • On-premise deployment — The entire platform can be deployed within the customer's own infrastructure, ensuring complete control over data location.

  • Bring-Your-Own-Cloud (BYOC) — Customers can host the platform on their own cloud tenancy in any region of their choice.

Q: What cloud infrastructure does We360.ai use?

We360.ai is deployed on enterprise-grade cloud infrastructure leveraging services including:

  • Managed Kubernetes clusters distributed across multiple availability zones for high availability

  • Managed relational databases (PostgreSQL) with encryption at rest

  • Columnar databases for analytics workloads

  • Encrypted object storage for screenshots and backups

  • Cloud-native identity and access management

  • Network segmentation with private subnets and firewall rules

The underlying cloud providers maintain their own extensive compliance certifications, including ISO 27001, ISO 27017, ISO 27018, SOC 1/2/3, PCI DSS, and CSA STAR.

Q: Is the infrastructure multi-tenant or single-tenant?

The cloud-hosted platform operates in a multi-tenant architecture with strict logical data separation:

  • Each customer's data is logically isolated to prevent cross-organization access.

  • Role-based access controls enforce tenant boundaries at every layer.

  • For customers requiring physical isolation, on-premise or BYOC deployment options provide dedicated single-tenant environments.


7. Access Controls & Authentication

Q: How does We360.ai control access to customer data?

We360.ai implements a comprehensive access control framework based on the principle of least privilege:

  • Role-Based Access Control (RBAC) — Users are assigned permissions based on their organizational role. Administrators can define granular access levels.

  • Least privilege — Users and system accounts are granted only the minimum access necessary to perform their responsibilities.

  • Multi-Factor Authentication (MFA) — Enforced for all privileged and administrative access, including cloud infrastructure management.

  • Single Sign-On (SSO) — Supported for enterprise customers, integrating with existing identity providers.

  • SCIM Provisioning — Custom SCIM (System for Cross-domain Identity Management) integration is available for enterprise customers. SCIM enables automated user provisioning and deprovisioning synchronized with the customer's identity provider (e.g., Azure AD, Okta, OneLogin), ensuring that user accounts in We360.ai are created, updated, and removed in lockstep with the organization's directory. This reduces manual administration overhead and eliminates the risk of orphaned accounts retaining access after employee offboarding. Contact We360.ai to scope a SCIM integration for your environment.

  • Inactive account deactivation — Accounts with no login activity for 30 days are automatically deactivated (can be reactivated upon request).

  • Dormant account removal — Accounts that remain deactivated and unused for 90 days are reviewed and permanently removed.

  • Quarterly access reviews — Periodic reviews ensure access permissions remain appropriate.

  • Immediate revocation on termination — Access is revoked immediately upon employee separation.

Q: What password policies does We360.ai enforce?

We360.ai enforces strong password management practices as documented in the Password Management Policy, including minimum complexity requirements, prohibition of password reuse, and event-driven password changes (e.g., upon suspected compromise) aligned with current NIST SP 800-63B guidance. MFA is required for privileged access as an additional layer of protection.

Q: How is administrative access to infrastructure managed?

Administrative access to cloud infrastructure and production systems is:

  • Restricted to authorized personnel only

  • Protected by MFA

  • Logged and auditable (all access activity is tracked)

  • Subject to periodic access reviews

  • Segregated by environment (development, staging, production)

Q: Are customer administrator actions logged and auditable?

Yes. All administrative actions performed within the We360.ai platform — including configuration changes, user management, access to employee data, modifications to Do Not Track lists, and policy changes — are logged in an immutable audit trail. These logs include the administrator identity, timestamp, action performed, and affected resources. Audit logs are available to customer administrators and can be exported for compliance and internal review purposes.


8. Incident Management & Breach Notification

Q: Does We360.ai have a formal incident management process?

Yes. We360.ai maintains a documented Incident Management Policy that defines:

  • Incident classification — Incidents are categorized by severity (Low, Moderate, High) and type (intrusion, malicious code, denial of service, unauthorized use, data breach, web defacement).

  • Incident Response Team (IRT) — A structured team with an executive sponsor responsible for coordinating response efforts.

  • Response procedures — Defined processes for detection, containment, eradication, recovery, and lessons learned.

  • Root Cause & Corrective Action (RCCA) — Post-incident analysis to identify root causes and implement corrective actions.

  • Security awareness training — Annual training for all personnel on security incident identification and reporting.

Q: How does We360.ai handle data breaches?

In the event of a data breach:

  • Immediate containment — The Incident Response Team takes prompt corrective action to contain the breach.

  • Assessment — The nature, scope, and impact of the breach are assessed.

  • Notification to the customer (Controller) — As a Data Processor, We360.ai commits to notifying the affected customer (the Data Controller) within 24 hours of becoming aware of a confirmed personal data breach. This notification includes:

    • Nature and scope of the breach

    • Categories and approximate number of data subjects and records affected

    • Likely consequences of the breach

    • Measures taken or proposed by We360.ai to contain and remediate the breach

    • Contact details of We360.ai's Data Protection Officer for ongoing coordination

    This 24-hour processor-to-controller SLA is designed to give the Controller sufficient time to fulfill its own downstream regulatory obligations:

    • GDPR (Article 33) — The Controller must notify the relevant supervisory authority within 72 hours of becoming aware of a breach. By notifying within 24 hours, We360.ai ensures the Controller retains at least 48 hours to assess the incident, determine reportability, and file its notification. Where the breach is likely to result in a high risk to the rights and freedoms of individuals, the Controller must also notify affected data subjects without undue delay (Article 34).

    • HIPAA — Notification in accordance with the HIPAA Breach Notification Rule timelines.

    • DPDP Act — Notification to the Data Protection Board and affected data principals as required under the Act.

  • Remediation — Corrective actions are implemented and documented.

  • Post-incident review — Lessons learned are incorporated into policies and controls.

Q: Does We360.ai maintain an incident register?

Yes. All security incidents are logged in an incident register with relevant details including classification, timeline, response actions, and resolution. This register supports audit requirements and continual improvement of the incident management process.


9. Vendor & Subprocessor Management

Q: How does We360.ai manage third-party vendors and subprocessors?

We360.ai maintains a formal Vendor Management Policy that governs the selection, assessment, and ongoing oversight of all third-party vendors and subprocessors:

  • Due diligence — All vendors undergo a security and compliance assessment before engagement, including evaluation of their own certifications, security controls, and data handling practices.

  • Contractual safeguards — Non-Disclosure Agreements (NDAs), Data Processing Agreements, and SLAs are required for all vendors handling customer data.

  • Critical vendor classification — Vendors are classified by criticality, with enhanced oversight for those processing sensitive data or providing critical services.

  • Periodic reviews — Vendor access and compliance status are reviewed periodically.

  • Vendor auditing — We360.ai reserves the right to audit vendor compliance with contractual and security obligations.

  • Cloud-specific controls — For cloud service providers, additional controls are enforced including data localization verification, encryption validation, and multi-tenant segregation assurance.

Q: Does We360.ai share data with subprocessors?

Data is shared with subprocessors only as necessary for service delivery (e.g., cloud hosting, payment processing, email delivery). All subprocessors are bound by confidentiality obligations and data processing agreements. A list of subprocessors can be provided upon request as part of the Data Processing Addendum.

We360.ai does not sell, rent, or commercially exploit customer data.


10. Business Continuity & Disaster Recovery

Q: Does We360.ai have a Business Continuity Plan (BCP)?

Yes. We360.ai maintains a comprehensive Business Continuity and Disaster Recovery (BC/DR) Policy based on Business Impact Analysis (BIA). The plan defines:

  • Maximum Acceptable Outage (MAO) — The maximum tolerable period of disruption.

  • Recovery Time Objective (RTO) — Target time to restore services after a disruption. Standard baseline RTO is 4 hours, though custom SLAs are available for enterprise customers. Detailed RTO targets per service tier are available upon request under NDA.

  • Recovery Point Objective (RPO) — Maximum acceptable data loss measured in time. Standard baseline RPO is 24 hours, though custom SLAs are available for enterprise customers. Detailed RPO targets per data category are available upon request under NDA.

  • Work-from-home provisions — Security guidelines for maintaining operations during office disruptions.

Q: How often is the BC/DR plan tested?

The BC/DR plan is tested regularly through multiple exercise types:

  • Tabletop exercises — Walkthrough of disaster scenarios with the response team.

  • Simulated exercises — Live simulation of failure scenarios.

  • Partial and complete recovery tests — Actual failover and recovery exercises.

Testing covers scenarios including single-node failure (automatic self-healing via Kubernetes), availability zone failure (multi-AZ failover), full database/cluster failure (backup restoration), and regional failure (infrastructure recreation from code plus backup restoration).

Q: How are backups managed?

  • Frequency — Daily automated database backups.

  • Retention — Backups retained for 1 month on a rolling basis.

  • Encryption — Backups are encrypted at rest.

  • Testing — Backup restoration is tested as part of DR exercises.

  • Infrastructure as Code — Infrastructure is defined in code, enabling rapid recreation of the entire environment from scratch if needed.


11. Stealth vs Standard Mode — Ethical Monitoring

Q: What is the difference between Stealth and Standard mode?

We360.ai offers two deployment modes, both delivering identical tracking capabilities:

Aspect
Standard Mode
Stealth Mode

Visibility

Visible to the employee — system tray icon and desktop application

Runs silently in the background — no visible UI

User interaction

Employees can punch in/out, pause tracking, view their own analytics

No user interaction; tracking is automatic based on configured shifts

Use case

Transparent monitoring environments where employee awareness and self-service are valued

Discreet monitoring where automated, policy-driven tracking is preferred

Admin rights

Not required for installation

Required for installation

Tracking capabilities

Full feature set

Identical full feature set

Security & encryption

Same standards

Same standards

Both modes provide:

  • Per-second activity granularity

  • App and URL tracking

  • Aggregate input activity (mouse/keyboard counts only — see Section 4 for definitive data collection boundaries)

  • Screenshots and screen recording (if configured)

  • Offline-first data sync

  • Encrypted data transmission and storage

We360.ai recommends that organizations deploying in Stealth mode:

  • Comply with all applicable local, regional, and national laws governing employee monitoring and workplace privacy.

  • Inform employees through workplace policies, employment agreements, or privacy notices as required by applicable law.

  • Use monitoring data for legitimate business purposes (productivity optimization, security, compliance) — not for punitive surveillance.

We360.ai's platform is designed to support ethical, proportionate, and policy-driven monitoring regardless of the deployment mode selected.

Q: Does We360.ai support monitoring only during work hours?

Yes. Shift-based tracking allows organizations to restrict monitoring to designated work hours and authorized environments. Outside of configured shifts, the agent does not capture activity data. This aligns with privacy principles of data minimization and purpose limitation.


12. On-Premise & BYOC Deployment

Q: Can We360.ai be deployed on our own infrastructure?

Yes. We360.ai offers two self-hosted deployment models:

VM-Based Deployment (recommended for up to 2,000 users):

  • Single Linux VM running containerized services

  • Customer-managed database and object storage

  • Suitable for organizations seeking simplicity with full data control

Kubernetes Deployment (recommended for 1,000+ users):

  • Kubernetes cluster with multiple worker nodes

  • Horizontally scalable for large enterprises

  • High-availability configuration with multi-node redundancy

Both options ensure that all data — including activity logs, screenshots, recordings, and backups — remains entirely within the customer's own infrastructure or cloud tenancy.

Q: What are the infrastructure requirements for on-premise deployment?

VM-Based:

  • Linux (Ubuntu Server LTS)

  • 16 CPU cores, 64 GB RAM, 512 GB SSD (resizable)

  • External S3-compatible object storage for screenshots and backups

  • PostgreSQL and ClickHouse databases (managed or self-hosted)

Kubernetes-Based:

  • Kubernetes v1.30+ cluster with 3–6 worker nodes

  • 8 cores / 32 GB RAM per worker node

  • CSI storage provisioner with 100+ GB SSD

  • Separate PostgreSQL and ClickHouse instances

Additional requirements:

  • SMTP server access for email functionality (TLS/STARTTLS/SSL supported)

  • Outbound internet access for license validation only (no customer data is transmitted)

Q: Does the on-premise deployment send any data back to We360.ai?

The on-premise deployment requires outbound connectivity to We360.ai's licensing server for tenant configuration and license validation only. No customer data, employee activity data, screenshots, or any monitoring data is transmitted to We360.ai's infrastructure. All collected data remains entirely within the customer's environment.

Q: Does the same data isolation apply to Bring-Your-Own-Cloud (BYOC) deployments?

Yes. The BYOC deployment model has the exact same data isolation guarantees as on-premise. In a BYOC deployment, the entire We360.ai platform runs within the customer's own cloud tenancy (e.g., their own AWS, Azure, or GCP account). Specifically:

  • All customer data stays in the customer's cloud tenancy — Activity logs, screenshots, screen recordings, database contents, backups, and all other monitoring data are stored and processed entirely within the customer's cloud account. No customer data is transmitted to We360.ai's infrastructure.

  • Outbound connectivity is limited to license validation only — Identical to on-premise, the only outbound connection to We360.ai is for tenant configuration and license validation. This connection transmits no customer data, employee activity data, or monitoring data of any kind.

  • Customer controls the infrastructure — The customer owns and manages the cloud account, network configuration, encryption keys, and access policies. We360.ai does not have standing access to the customer's cloud tenancy unless explicitly granted for support purposes.

  • Region and jurisdiction control — The customer selects the cloud region, ensuring full control over data residency and sovereignty.

In summary: Whether deployed on-premise or via BYOC, We360.ai operates under the same strict principle: all monitoring data remains within the customer's environment; only license validation traffic is exchanged with We360.ai.

Q: What platforms does the We360.ai agent support?

Platform
Support

Windows

Windows 10 and later (x86-64)

macOS

macOS 10.13 (High Sierra) and later — Intel and Apple Silicon

Linux

Ubuntu and Ubuntu-based distributions (e.g., Linux Mint, Pop!_OS). On-premise server deployment requires Ubuntu Server LTS.

iOS

Available on the Apple App Store

Android

Available on the Google Play Store

Chrome

Browser extension for enhanced web activity tracking

Virtual Desktops

Full support for Citrix, RDP, and VDI environments


Disclaimer: This section is for informational purposes only and does not constitute legal advice. Organizations should consult qualified legal counsel for jurisdiction-specific guidance on employee monitoring requirements.

Yes. Employee monitoring is legal in most jurisdictions worldwide, provided it is conducted in compliance with applicable laws regarding notice, consent, proportionality, and data protection. The legality depends on the jurisdiction, the type of monitoring, and the safeguards in place.

We360.ai is designed to help organizations monitor workforce activity lawfully by providing configurable controls, transparency features, and compliance-aligned defaults.

India does not have a single unified employee monitoring statute, but several laws and frameworks govern the practice:

  • Information Technology Act, 2000 (IT Act) — Section 43A requires bodies corporate that possess, deal with, or handle sensitive personal data to implement reasonable security practices. The IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 require that organizations collecting personal information provide a privacy policy, obtain consent, and use data only for the stated purpose.

  • Digital Personal Data Protection (DPDP) Act, 2023 — Establishes consent-based processing, purpose limitation, data minimization, and data principal rights (access, correction, erasure). Employers must have a valid legal basis for processing employee data and must provide clear notice about what data is collected and why.

  • State-specific Shops & Establishments Acts — Various Indian states have legislation governing working conditions, record-keeping, and employee rights that may impact monitoring practices.

  • Employment agreements and standing orders — Organizations should include monitoring disclosures in employment contracts, offer letters, or company policies to ensure employees are informed.

We360.ai's approach: The platform supports configurable consent mechanisms, purpose limitation through shift-based tracking, data minimization controls, and full data subject rights — aligning with the DPDP Act and IT Act requirements.

Q: What are the key employee monitoring laws in the United States?

Employee monitoring in the US is governed by a combination of federal and state laws:

Federal Laws:

Law
Relevance

Electronic Communications Privacy Act (ECPA)

Permits employer monitoring of electronic communications on company-owned systems, particularly when employees are notified or consent is provided.

Computer Fraud and Abuse Act (CFAA)

Prohibits unauthorized access to computer systems; relevant when monitoring extends to non-company devices.

National Labor Relations Act (NLRA)

Section 7 protects employees' rights to organize; monitoring must not be used to surveil or suppress protected concerted activity.

Americans with Disabilities Act (ADA)

Monitoring data related to disability or medical conditions must be kept confidential and handled appropriately.

Fair Labor Standards Act (FLSA)

Employers must maintain accurate records of hours worked; time-tracking tools support FLSA compliance.

State-Specific Requirements:

Several US states have enacted specific employee monitoring notification or consent requirements:

State
Key Requirement

Connecticut

Written notice to employees prior to electronic monitoring (Public Act 98-142).

Delaware

Written notice required before monitoring email, internet access, or telephone use (Delaware Code Title 19, §705).

New York

Written notice and conspicuous posting required when monitoring telephone, email, or internet usage (Civil Rights Law §52-c).

California

CCPA/CPRA grants employees data access, correction, deletion, and opt-out rights. General privacy protections under the California Constitution.

Texas

CUBI Act regulates collection of biometric identifiers.

Illinois

Biometric Information Privacy Act (BIPA) requires informed written consent before collecting biometric data.

Q: What are the key employee monitoring requirements under EU/UK law?

Under the General Data Protection Regulation (GDPR) and UK GDPR, employee monitoring must comply with the following principles:

  • Lawfulness, fairness, and transparency — A valid legal basis is required (typically legitimate interest or contractual necessity; consent is generally not considered freely given in an employment context due to the power imbalance).

  • Purpose limitation — Monitoring must be conducted for specified, explicit, and legitimate purposes.

  • Data minimization — Only data that is adequate, relevant, and limited to the stated purpose should be collected.

  • Storage limitation — Data must not be retained longer than necessary.

  • Data Protection Impact Assessment (DPIA) — Required when monitoring is likely to result in a high risk to employee rights and freedoms (see Section 17).

  • Employee notification — Employees must be informed about the monitoring, its purpose, and their rights before monitoring begins.

  • Data subject rights — Right to access, rectification, erasure, portability, restriction, and objection must be supported.

National laws within EU member states may impose additional requirements (e.g., works council consultation in Germany, CNIL guidelines in France).

Q: How does We360.ai help organizations comply with monitoring laws?

We360.ai provides built-in features that support legal compliance across jurisdictions:

  • Configurable tracking scope — Administrators can enable or disable specific data collection features to match local legal requirements.

  • Shift-based tracking — Restricts monitoring to designated work hours, preventing off-duty surveillance.

  • Do Not Track list — Excludes specific users from monitoring entirely (see Section 14).

  • Screenshot blurring (Blur Engine) — Masks sensitive on-screen content to prevent inadvertent capture of personal data.

  • Standard mode with employee visibility — Provides full transparency to employees about what is being tracked.

  • Data subject rights support — Built-in mechanisms for data access, export, correction, and deletion requests.

  • Data Processing Addendum (DPA) — Available with Standard Contractual Clauses for international data transfers.

  • Retention controls — Configurable data retention aligned with applicable legal requirements.

Note: We360.ai provides technology and tools to support compliance. It is the deploying organization's responsibility to ensure that its use of the platform complies with all applicable laws, including obtaining any required notice, consent, or works council approval.


14. Privacy Controls & Do Not Track

Q: Does We360.ai support a Do Not Track (DNT) list?

Yes. We360.ai provides a Do Not Track (DNT) feature that allows administrators to exclude specific employees or user accounts from all monitoring and data collection. Users placed on the DNT list:

  • Are not tracked by the We360.ai agent

  • Have no activity data, screenshots, or recordings collected

  • Do not appear in productivity reports or analytics dashboards

This is useful for exempting executives, HR personnel, legal teams, works council members, or any employees who should not be monitored due to legal, contractual, or policy reasons.

Q: What privacy controls does We360.ai provide?

We360.ai offers a layered set of privacy controls to help organizations implement proportionate and ethical monitoring:

Privacy Control
Description

Do Not Track (DNT) list

Completely exclude specific users from all monitoring.

Shift-based tracking

Restrict monitoring to designated work hours only. No data is captured outside configured shifts.

Screenshot blurring (Blur Engine)

Automatically mask/blur sensitive on-screen content (personal communications, financial data, authentication fields) in captured screenshots.

Screenshot frequency control

Adjustable from 2 to 60 per hour, or disabled entirely.

Screen recording toggle

Screen recording is off by default and must be explicitly enabled.

URL/app scope control

Configure which applications and websites are tracked via productivity rules and blocklists.

GPS tracking opt-in

Field/GPS tracking applies only to the mobile app and must be explicitly enabled.

Employee self-service (Standard mode)

Employees can view their own data, providing transparency into what is tracked.

Q: Can employees request to be excluded from monitoring?

Depending on the organization's policies and applicable local laws, employees may have the right to request exclusion from monitoring. We360.ai's Do Not Track list provides the technical mechanism to implement such exclusions. The decision to honor exclusion requests is made by the deploying organization in accordance with its HR policies, legal obligations, and collective agreements.

Under GDPR, employees have the right to object to processing based on legitimate interest; the organization must then assess whether its grounds override the employee's objection.

Q: Are privacy controls enabled by default?

We360.ai is designed with privacy-conscious defaults:

  • Screenshot blurring (Blur Engine) is available and configurable from the outset.

  • Screen recording is off by default — it must be explicitly enabled by an administrator.

  • GPS/location tracking is off by default — it applies only to the mobile app and requires explicit activation.

  • No keylogging, webcam, camera, microphone, or audio data collection — ever. See Section 4 for the definitive list of data collection boundaries.


15. Workforce Analytics vs. Surveillance

Q: How is We360.ai different from employee surveillance software?

We360.ai is a workforce analytics and productivity optimization platform — not a surveillance tool. The distinction is important:

Aspect
Surveillance Tools
We360.ai (Workforce Analytics)

Purpose

Monitor and record individual behavior for punitive oversight

Provide actionable productivity insights for teams and organizations

Data approach

Capture everything possible (keystrokes, camera feeds, personal content)

Collect only business-relevant activity data with configurable scope. See Section 4 for definitive boundaries.

Employee visibility

Typically hidden from employees

Standard mode provides full transparency; employees can view their own data

Privacy controls

Minimal or none

Blur Engine, DNT list, shift-based tracking, screenshot controls

Output

Raw surveillance logs for individual scrutiny

Aggregated analytics, trends, and productivity metrics

Keylogging

Often included

Never — see Section 4

Camera/audio capture

Common

Never — see Section 4

Q: What is We360.ai designed to be used for?

We360.ai is designed for legitimate business purposes, including:

  • Productivity optimization — Understanding how teams spend their time across applications and tasks.

  • Workforce planning — Data-driven decisions about workload distribution and capacity.

  • Time and attendance — Automated time tracking and attendance management.

  • Compliance and security — Monitoring for policy violations, data exfiltration risks, and insider threats.

  • Operational efficiency — Identifying workflow bottlenecks and optimizing tool usage.

  • Remote workforce management — Maintaining visibility and accountability for distributed teams.

We360.ai recommends that deploying organizations use monitoring data constructively — for coaching, process improvement, and organizational decision-making — rather than punitive individual surveillance.

Q: Does We360.ai perform keylogging?

No. We360.ai does not and cannot perform keylogging. For the complete, definitive statement on all data that We360.ai does not collect — including keylogging, webcam, audio, and personal file access — see Section 4: Data Collection & What Is NOT Collected. The platform captures only aggregate keystroke and mouse-click frequency counts as an activity indicator.


16. Employee Transparency & Data Access Rights

Q: What information can employees see about their own monitoring?

In Standard mode, employees have access to a personal dashboard showing their own productivity analytics, including:

  • Time tracked and attendance records

  • Application and website usage summaries

  • Productivity scores and trends

  • Activity timelines

This transparency allows employees to self-assess, understand how their time is spent, and improve their workflows. It also supports data protection principles by ensuring data subjects can verify what data is held about them.

Q: How can employees exercise their data protection rights?

We360.ai supports data subject rights as required by GDPR, DPDP Act, CCPA, and other applicable regulations:

Right
How It Is Supported

Right to be informed

Organizations are expected to notify employees about monitoring practices via policies, employment agreements, or privacy notices. Standard mode provides real-time transparency.

Right of access

Employees can access their own data via the Standard mode dashboard. Organizations can also export and provide data upon request.

Right to rectification

Data inaccuracies can be corrected through administrative controls.

Right to erasure

Administrators can delete individual user data upon request. Data is also deleted automatically per the retention policy.

Right to data portability

Data can be exported in standard formats for portability purposes.

Right to restrict processing

The Do Not Track list allows organizations to cease processing for specific individuals. Shift-based tracking restricts the scope of processing.

Right to object

Organizations can evaluate objections and use the DNT list or other controls to implement the outcome.

Requests are processed in accordance with the applicable regulatory timeline (e.g., one month under GDPR, as soon as reasonably practicable under DPDP Act).

Q: Does We360.ai notify employees that they are being monitored?

The notification mechanism depends on the deployment mode:

  • Standard mode — The We360.ai application is visible on the employee's system (system tray icon and desktop application). The employee is inherently aware of the monitoring.

  • Stealth mode — The application runs silently. It is the deploying organization's responsibility to inform employees through workplace policies, employment contracts, or privacy notices as required by applicable law.

We360.ai recommends that all organizations, regardless of deployment mode, maintain transparent communication with employees about monitoring practices to build trust and meet legal requirements.


17. Data Protection Impact Assessment (DPIA)

Q: When is a DPIA required for employee monitoring?

Under GDPR (Article 35) and equivalent regulations, a Data Protection Impact Assessment is required when processing is likely to result in a high risk to the rights and freedoms of individuals. Employee monitoring commonly triggers a DPIA requirement when it involves:

  • Systematic monitoring — Regular, ongoing tracking of employee activity across applications, websites, and systems.

  • Large-scale processing — Monitoring across a significant number of employees or an entire organization.

  • Sensitive data — Processing that may incidentally capture health information, union membership, or other special category data.

  • New or intrusive technologies — Deploying monitoring tools that use automated decision-making, biometric data, or novel data collection methods.

  • Evaluation or scoring — Using monitoring data for performance evaluation, profiling, or productivity scoring.

Most deployments of workforce analytics software, including We360.ai, are likely to require a DPIA under GDPR.

Q: How does We360.ai support DPIA completion?

We360.ai provides the information and controls needed to conduct a thorough DPIA:

  • Data inventory — Clear documentation of all data types collected, processing purposes, and retention periods (see Section 4).

  • Configurable data collection — Ability to minimize data collection to only what is necessary for the stated purpose, supporting the proportionality assessment.

  • Privacy controls documentation — Blur Engine, DNT list, shift-based tracking, and other safeguards that serve as risk mitigation measures in the DPIA.

  • Security controls — Encryption, access controls, and incident management processes documented in this FAQ serve as technical and organizational measures.

  • Data flow information — Architecture and data flow diagrams available upon request to map how data moves through the system.

  • Subprocessor information — List of subprocessors and their roles available as part of the DPA, supporting the third-party risk assessment.

  • Deployment flexibility — On-premise and BYOC options allow organizations to reduce risk by keeping data within their own infrastructure.

Tip: Organizations should complete a DPIA before deploying We360.ai and review it periodically or when making significant changes to the monitoring configuration. We360.ai's team can provide supporting documentation upon request.

Q: Is a DPIA required under India's DPDP Act?

The DPDP Act 2023 does not explicitly mandate a DPIA in the same manner as GDPR. However, it requires Data Fiduciaries to implement appropriate technical and organizational measures to protect personal data and to demonstrate compliance. Conducting a privacy impact assessment is considered a best practice for organizations deploying employee monitoring tools in India and may be required for Significant Data Fiduciaries as designated by the government.


18. Remote, Hybrid & BYOD Workforce Monitoring

Q: How does We360.ai support monitoring for remote and hybrid workforces?

We360.ai is built for distributed workforce environments. The agent operates identically whether the employee is in the office, working from home, or at a remote location:

  • No VPN dependency — The agent communicates with We360.ai's backend over standard HTTPS (port 443). No VPN, corporate network, or special network configuration is required.

  • Offline-first architecture — If the employee's internet connection is intermittent, activity data is stored locally in an encrypted database and synced automatically when connectivity is restored.

  • Shift-based tracking — Ensures monitoring is limited to work hours regardless of the employee's physical location, respecting work-life boundaries.

  • Multi-platform support — Agents available for Windows, macOS, Linux, iOS, Android, and Chrome, covering all common remote work environments.

  • Location-agnostic analytics — Productivity metrics are calculated consistently regardless of whether the employee is onsite or remote.

Q: Does We360.ai support BYOD (Bring Your Own Device) environments?

Yes, We360.ai can be deployed on both company-owned and employee-owned devices. However, organizations deploying on personal devices should consider:

  • Legal requirements — Many jurisdictions require explicit, informed consent before monitoring personal devices. Organizations should ensure appropriate consent mechanisms are in place.

  • Scope limitation — Use shift-based tracking to restrict monitoring strictly to work hours, preventing capture of personal activity.

  • Privacy controls — Enable the Blur Engine and configure URL/app blocklists to minimize incidental capture of personal data.

  • Employee communication — Clearly communicate the scope and limitations of monitoring on personal devices via policies or agreements.

  • Standard mode recommended — Standard mode provides full transparency to the employee, which is particularly important on personal devices where the expectation of privacy is higher.

We360.ai does not access personal files, camera feeds, microphone, or audio on any device — company-owned or personal. For the definitive list of data collection boundaries, see Section 4.

Q: How does We360.ai ensure work-life balance boundaries?

We360.ai provides several mechanisms to ensure monitoring respects work-life boundaries:

  • Shift-based tracking — Monitoring activates only during configured work shifts and deactivates automatically outside those hours. No activity data is captured during off-hours.

  • Do Not Track list — Employees can be exempted entirely during specific periods or permanently.

  • No always-on monitoring — Unlike some surveillance tools, We360.ai does not continuously monitor 24/7 unless explicitly configured by the organization to do so.

  • Standard mode controls — In Standard mode, employees can see when tracking is active, providing clarity on monitoring boundaries.

  • GPS tracking only when enabled — Field location tracking applies only to the mobile app and only when explicitly activated by the organization.


Contact

For compliance inquiries, documentation requests, or to schedule a security review:

  • Data Protection Officer: dpo@we360.ai

  • Security & Vulnerability Reporting: security@we360.ai

  • General Support: support@we360.ai

We360.ai is committed to transparency and will work with your security and compliance teams to address any additional questions during the vendor evaluation process.

Last updated

Was this helpful?