Skip to main content

Trust

Infrastructure your customers can depend on.

GroWrk Embedded is evaluated by enterprise IT, security, and procurement teams. These are the controls that govern partner integrations and the physical operations behind them.

  • SOC 2 Type 2
  • Scoped API keys
  • OAuth 2.1 for MCP
  • Certified disposition

Security program

SOC 2 Type 2 controls govern the platform and the operating processes behind it.

Authentication

Scoped API keys for REST, authenticated CLI sessions, and OAuth 2.1 for MCP clients.

Permissions

Role and scope based access per partner tenant, applied identically across API, CLI, and MCP.

Auditability

Order history and lifecycle events give every device a traceable record.

Enterprise controls

  • Order validation and approval steps before execution
  • Separate sandbox and production environments
  • Certified wiping and documented disposition at end of life
  • Lifecycle events available to your systems of record

Reviewing GroWrk for an enterprise program?

We will walk your security and IT teams through the controls and evidence.

Talk to Embedded Team