Preparing your experience
Preparing your experience
How WorkflowGym protects your member records, payment transactions, and gym operations with industry-standard encryption, multi-tenant isolation, and daily backups.
TLS 1.3 encryption in transit
Strict multi-tenant security
Automated cloud recovery
Razorpay payment vault
Every gym on WorkflowGym operates in a strictly scoped multi-tenant environment. Database queries, member profiles, attendance logs, and financial records are automatically scoped to your unique gym ID. No gym can query, access, or expose another gym's data.
WorkflowGym provides granular staff permissions. Gym owners can assign restricted roles (Receptionist, Trainer, Branch Manager) ensuring that front-desk staff can record check-ins and payments without accessing overall profit/loss reports or exporting member databases.
All communications between your browser, mobile devices, and WorkflowGym servers are encrypted using modern TLS 1.3 / 256-bit SSL protocols. Unencrypted HTTP requests are automatically upgraded to secure HTTPS.
Passwords and sensitive authentication tokens are hashed using industry-standard one-way cryptographic algorithms (Bcrypt/Argon2) with unique salts. WorkflowGym staff cannot view your plaintext passwords under any circumstances.
Sensitive database fields and daily storage backups are encrypted at rest using AES-256 standard encryption.
WorkflowGym integrates natively with Razorpay for online payments and UPI collection. We do NOT store credit/debit card numbers, CVV codes, or net-banking passwords on our application servers.
All card payments and UPI transactions are handled directly by PCI-DSS Level 1 certified payment gateways. Funds settle directly into your linked gym bank account with zero platform commission from WorkflowGym.
WorkflowGym runs automated daily snapshots and database backups stored across isolated cloud locations to prevent data loss in the event of hardware or data center failure.
Our application and database clusters are monitored 24/7 with automated health checks, rate limiting, and DDoS mitigation to maintain a 99.9% uptime SLA.
You own 100% of your gym's data. You can export member registers, payment histories, and attendance logs to CSV or Excel at any time directly from your dashboard.
Our engineering team regularly reviews dependencies, monitors CVE advisories, and applies security patches immediately upon availability.
If you are a security researcher and discover a potential vulnerability within WorkflowGym, please report it directly to info@workflowgym.com. We acknowledge valid reports within 48 hours and work expeditiously to remediate findings.
Our engineering team is happy to answer technical architecture questions.