Security

Last updated: April 30, 2026

This is a template. Replace with content reviewed by your security and legal teams before going live.

Security is foundational at TaskTap.ai. We design, build, and operate the Service so that your team's data stays private, available, and under your control.

1. Our approach

We follow the principle of least privilege, defense in depth, and secure-by-default engineering. Every change is peer-reviewed, every deployment is automated and audited, and we run regular internal and third-party security testing.

2. Data encryption

All traffic between you and TaskTap.ai is encrypted in transit using TLS 1.2 or higher. Data at rest is encrypted using AES-256. Encryption keys are managed by our cloud provider's key management service and rotated regularly.

3. Access controls

Multi-factor authentication is available to every user and required for administrators. SSO via SAML 2.0 and SCIM user provisioning are available on our Enterprise plan. Internal access to production systems is gated by hardware-backed MFA, time-bounded grants, and full audit logging.

4. Infrastructure

TaskTap.ai runs on a major cloud provider in geographically isolated regions. Customer data is logically isolated per tenant. Production environments are separated from staging and development, with no shared credentials between them.

5. Backups and disaster recovery

We take encrypted backups of customer data on a continuous basis with point-in-time recovery. Backups are tested regularly. Our recovery objectives target an RPO of under 15 minutes and an RTO of under 4 hours for major regional incidents.

6. Compliance

We are working toward SOC 2 Type II certification and follow GDPR for users in the European Economic Area and the UK. Data Processing Addenda are available on request for Pro and Enterprise customers.

7. Vulnerability disclosure

If you believe you've found a security issue in TaskTap.ai, we want to hear from you. Email security@taskflow.com with a description and reproduction steps. We aim to acknowledge reports within one business day and will keep you informed as we investigate.

8. Contact

For other security or compliance questions, email security@taskflow.com.