# Private connectivity

Workato offers the following private connectivity options for an enhanced level of security and data protection:

AWS PrivateLink (opens new window) uses private endpoints to connect an AWS Virtual Private Cloud (VPC) to the Workato multi-tenant cloud without traversing the public internet. This connection provides secure access to OPA-capable connectors and Workato's API platform.

Refer to the AWS PrivateLink page for more information about AWS PrivateLink, including setup instructions.

Azure Private Link (opens new window) uses private endpoints to connect an Azure Virtual Network (VNet) to the Workato multi-tenant cloud without traversing the public internet. This connection provides secure access to OPA-capable connectors and Workato's API platform.

Refer to the Azure Private Link page for more information about Azure Private Link, including setup instructions.

# On-prem agent

The Workato on-prem agent (OPA) supports secure data transfer to Workato without requiring inbound firewall openings and allows Workato to access applications that are only available from the user's private network. OPA establishes an outbound connection from a user’s network to Workato’s cloud gateways, allowing for TLS-encrypted data transfer over the public internet.

Refer to the Accessing on-prem section for more information about OPA, including setup instructions.

# Virtual Private Workato

Virtual Private Workato (VPW) offers a dedicated private Workato instance separate from Workato’s commercial cloud environment. VPW is hosted in its own AWS Virtual Private Cloud (VPC) and connected through VPC peering and transit gateway to customer external networks. VPW is ideal for customers with strict compliance, data residency, or security requirements.

Refer to the VPW page for more information about Virtual Private Workato.


Last updated: 8/11/2025, 7:29:50 PM