Security, Privacy & Compliance
We pledge to keep your data secure, follow security best practices, and never sell or share your data with any third party.
SOC 2 Type 2, GDPR and CASA Tier 2 / Tier 3 compliance
As of April 1, 2024, we are proud to announce our compliance with the AICPA SOC 2 Type 2 standards, ensuring that our systems and processes meet rigorous criteria for security.
Additionally, we adhere to the EU’s GDPR compliance checklist for US companies, affirming our commitment to data protection and privacy for our international users.
Furthermore, WIQ meets the stringent requirements of Tier 2 and Tier 3 of the Cloud Application Security Assessment (CASA) as defined by the App Defense Alliance, built upon the industry-recognized OWASP Application Security Verification Standard (ASVS).
Your data
WIQ is built for enterprises with strict privacy requirements. A lightweight browser extension and desktop app passively capture the interactions needed to reconstruct how your processes are run — and you decide exactly what is captured through allowlist/blocklist controls and capture windows scoped to specific apps, domains, or time periods.
Captured activity is used solely to map your processes and generate automation blueprints. It is never used to train external models, and access is governed by your organization’s retention and residency policies.
WIQ is a process-intelligence tool for building automations, not an employee-monitoring product. Analytics measure process handle times and conformance — not individual performance — and captured data is never sold or shared with any third party.
All data is exchanged between your client and our servers using industry-standard technologies and protocols, encrypted in transit and at rest.
Deleting account and removing all data
We hate to see our users go. You can remove all your data from WIQ from your account settings, or email us at support@getwiq.ai and we will take care of it for you.
What information do we collect?
To build a product that people love, we need to understand how our users use it. We collect basic information such as how many active users we have, which features they use, and the errors that happen so we can fix them.
We use Amplitude to store aggregated usage and telemetry information. We use Statsig for experimentation and dynamic configuration, and Sentry to store anonymized error and crash reports.
For more detailed information, please visit our Privacy Policy page or contact us.
How we secure captured workflow data
WIQ operates within a comprehensive security framework designed for regulated industries, ensuring your workflow data remains protected throughout the observation, understanding, and automation stages.
All workflow event streams captured during the observation phase are handled with the same SOC 2 Type 2 compliant infrastructure that powers the rest of the platform, using TLS 1.2 for in-transit data protection and 256-bit AES encryption for data at rest. The data derived from observed interactions is processed securely to reconstruct process patterns while maintaining strict privacy controls.
The automation blueprints and AI agents generated by WIQ inherit the same stringent security controls that govern the platform, ensuring your workflows maintain confidentiality, integrity, and availability.
Captured workflow data is never sold or shared with any third party, aligning with our core security pledge and GDPR compliance standards.
Controls over what WIQ captures
The WIQ browser extension and desktop app request only the access needed to observe the interactions they are permitted to capture. You stay in control of that scope at all times:
Allowlist / blocklist
You decide exactly which apps and domains WIQ is allowed to capture from. Anything outside the allowlist — or explicitly on the blocklist — is never observed.
Capture windows
Capture can be scoped to specific time periods, so WIQ only observes work during the windows you define and stays dormant otherwise.
Individual controls
In addition to organization-wide admin settings, individual users can start, pause, and stop their own capture, so people decide exactly what data gets captured and when.
Data residency & retention
Captured data is governed by your organization’s data residency and retention policies, and is used only to map your processes and generate automation blueprints. It is never used to train external models, and never sold or shared with any third party.
Encryption and other information
- WIQ uses TLS 1.2 for securing in-transit data as well 256-bit AES encryption at rest on our cloud infrastructure.
- Infrastructure as code: all our infrastructure services are deployed using declarative configuration, all changes are versioned and stored.
- All code changes undergo a peer-review.
- The code is automatically scanned for known security vulnerabilities and patches are applied in a timely manner.
Security contact
Please send any security related information or inquiries (including vulnerability disclosures) to security@getwiq.ai
Frequently asked questions
Is my data secure and private? +
Yes. WIQ is built for enterprises with strict privacy requirements. Everything runs within a security framework designed for regulated industries, with granular allowlist/blocklist controls, configurable capture windows, and data residency and retention policies that meet your compliance requirements.
What data does WIQ capture? +
WIQ captures browser and desktop interactions – clicks, navigation, and page content – to reconstruct how processes are executed. You decide exactly what gets captured through allowlist/blocklist controls and capture windows scoped to specific apps, domains, or time periods.
How will my data be used? +
Captured activity is used solely to map your processes and generate automation blueprints. It is not used to train external models, and access is governed by your organization's retention and residency policies.
Will my data be used for performance management? +
No. WIQ is a process-intelligence tool for building automations, not an employee-monitoring product. Analytics measure process handle times and conformance, not individual performance.
Can individual users control their own recording? +
Yes. Individual users can control their own capture in addition to org-admin controls, so people decide exactly what data gets captured and when.
What agentic platforms does WIQ support? +
WIQ generates blueprints optimized for the major agentic platforms, including Claude, Workato, and Microsoft Copilot, so you can deploy on the platform your enterprise already uses.
How does WIQ connect to my agentic platform? +
WIQ brings critical process context and agent design to your enterprise MCP platform, delivering blueprints with the skills, tools, and integrations an agent needs to run on your chosen platform.
What is a blueprint? +
A blueprint is everything an AI agent needs to do the job – skills, tools, and integrations – all built from real human examples of how the process is actually performed.
What tools and systems does WIQ work with? +
WIQ checks your environment for the tools an agent needs – APIs, MCP servers, and documents. If a required tool doesn't exist, WIQ's AI-powered builder helps you create it.
How does WIQ discover processes? +
A lightweight browser extension and desktop app passively capture human interactions to reconstruct how processes are run every day, mapping every variation across the browser and desktop.
Do users have to change how they work? +
No. WIQ maps work passively while people work normally – there's no new workflow to adopt. A single week of data is enough to map variations, identify bottlenecks, and benchmark productivity.
Can I map a single process instead of my whole operation? +
Yes. Use Quick Capture to record a single process end-to-end on video, and WIQ generates a full automation blueprint from that single run – ideal for ad hoc automations.
Do I need to write automation specs manually? +
No. WIQ generates automation blueprints automatically from real human examples, optimized for your agentic platform – no manual spec-writing required.
What happens when a process changes? +
Because WIQ maps processes continuously, it surfaces new variations as work evolves, so blueprints can be kept in step with how the process is actually run.
How does WIQ calculate time savings? +
WIQ measures the actual time a human spends actively working a process – not resolution time with idle minutes – so you can prioritize the workflows where automation delivers the most value.
How do I deploy agents? +
Each human operator can deploy concurrent AI agents that complete tasks autonomously, each following the right blueprint for the job.
Can I run multiple agents at the same time? +
Yes. Launch many concurrent agent sessions to chew through the task backlog – one operator can run a whole fleet.
How does WIQ monitor agent performance? +
WIQ monitors each agent's chain of thought for conformance to the blueprint, and tracks SLAs, handle times, and process conformance in one place – whether work was done by a person or an agent – so you can scale the fleet without scaling the risk.
How long does setup take? +
Setup is lightweight: install the browser extension, work normally for about a week while WIQ maps your processes, then review the discovered process maps. You can deploy a first agent in under a week.
Do I need engineering resources to get started? +
No engineering is required. WIQ maps processes passively and generates blueprints automatically, so you can get to a deployed agent without building integrations by hand.