Is there a self-serve tier?
Not yet. WorkReef governs decisions that affect people's roles and a company's AI spend. The work to bootstrap a new tenant benefits from a real conversation. We'll open self-serve once the playbook is mature enough that it doesn't.
What's the commitment?
The design partner agreement is a six-month term. We expect honest feedback and the occasional reference call. You can terminate at any point with thirty days' notice, and tenant data export is one click in admin settings.
What does implementation look like?
Connect three integrations. Run the Cartographer pass. Approve the persona assignments in bulk. Review the first wave of transformation proposals. From signup to "the platform is making real recommendations" is typically days, not weeks, assuming your stack is on the catalog.
Can we use our own LLM provider?
Yes. Per-customer inference routing is in the platform from day zero: Azure OpenAI, Amazon Bedrock, on-prem, or a mix. Model allowlist enforced on the server. The rest of the platform doesn't change when you pick a different backend.
What about HIPAA / SOC 2?
Our current security posture is on the Security page: what's done, what's mid-stride, what's deferred. Formal attestations are on the Enterprise tier roadmap. For HIPAA-relevant deployments (Movemedical is customer one) we work the BAA path as part of onboarding.
Do we own our data?
Yes. Each customer's data lives in its own isolated database, separate from every other customer at the storage layer. Bring your own key with Azure Key Vault, AWS KMS, or GCP KMS ships with the Enterprise tier. Export and right-to-be-forgotten are one-click admin flows.
What if we want to leave?
Export drops a zip with every table from your tenant database, credentials redacted. No proprietary file format. No special lock-in. The connectors keep working pointed at whatever you switch to.
What if the agents are wrong?
The drive layer is reversible. Promotion forward requires thirty shadow runs at eighty-five-percent agreement. Backward moves (autonomous to assist to off) are always allowed. Per-action approval gates block sensitive moves until a named approver releases them. The audit log records who approved what, when, and what fired afterward.