Workhuman publishes its security and compliance posture on a Security & Privacy page rather than a trust. portal (trust.workhuman.com and security.workhuman.com do not resolve, which is why the automated trust-center probe recorded no hit — this is the searched, human-verified fill). The page states Workhuman is ISO 27001:2022 and ISO 27701:2019 certified with the certification covering the full scope of services provided, is a PCI DSS Level 3 certified merchant (its payments provider is PCI DSS Level 1), is compliant with GDPR and CCPA, and conducts third-party audits twice annually. The company's llms.txt (llms/workhuman-llms.txt, last updated 2026-07-14) repeats these claims and adds that its responsible-AI governance posture aligns with the NIST AI Risk Management Framework and ISO/IEC 23894:2023.
Workhuman maintains a public trust center documenting ISO 27001, ISO 27701, and PCI DSS compliance.