Trust
Infrastructure your customers can depend on.
GroWrk Embedded is evaluated by enterprise IT, security, and procurement teams. These are the controls that govern partner integrations and the physical operations behind them.
- SOC 2 Type 2
- Scoped API keys
- OAuth 2.1 for MCP
- Certified disposition
Security program
SOC 2 Type 2 controls govern the platform and the operating processes behind it.
Authentication
Scoped API keys for REST, authenticated CLI sessions, and OAuth 2.1 for MCP clients.
Permissions
Role and scope based access per partner tenant, applied identically across API, CLI, and MCP.
Auditability
Order history and lifecycle events give every device a traceable record.
Enterprise controls
- Order validation and approval steps before execution
- Separate sandbox and production environments
- Certified wiping and documented disposition at end of life
- Lifecycle events available to your systems of record
Reviewing GroWrk for an enterprise program?
We will walk your security and IT teams through the controls and evidence.
