Security & Trust
Last updated: September 25, 2026
Taskpend holds your team's tasks, documents and the work your AI agents do on them. This page states plainly how that data is protected. Questions, or a security review to complete? Write to support@taskpend.com.
Encryption
- In transit: all traffic to Taskpend and its API is encrypted with TLS (HTTPS). Plain HTTP is redirected to HTTPS, and HTTP Strict Transport Security (HSTS) is enforced for one year, including subdomains.
- At rest: your data is stored in a managed PostgreSQL database run by Supabase on Amazon Web Services, encrypted at rest with AES-256.
Accounts and access
- Sign-in: email and password, or Sign in with Google (OAuth). Passwords are hashed by our authentication provider and never stored in plain text.
- Multi-factor authentication: coming soon.
- Workspace isolation: workspace data is protected by row-level security in the database, so a request can only reach data in the workspace of the person making it.
- Personal sources stay personal: a mailbox, calendar or Drive is only ever read through the connection of the person who connected it — never through a colleague's.
Connected tools
- Integrations (Google, Slack, Jira, GitHub) are connected by OAuth, with your explicit consent on the provider's own screen.
- Access tokens are kept server-side only. They are never sent to the browser and cannot be read by other members of your workspace.
- You can disconnect any integration at any time from Settings → Connectors.
AI and your data
- Your data is not used to train AI models. We don't train on it, and our primary AI provider, Anthropic, does not train on data sent through its commercial API.
- Agents work only on what you ask them to, inside your workspace, and never take irreversible actions. Code changes arrive as pull requests that you review and merge yourself; in a conversation, documents and task changes are shown for review before they are saved.
Your data, your control
- You own the content you create. We process it only to provide the service.
- When you delete your account, we delete or anonymize your data within 30 days, unless the law requires us to keep it.
- You can ask us for a copy of your data, or to correct or delete it, at privacy@taskpend.com.
Compliance
- GDPR: we process personal data in line with the GDPR — see our Privacy Policy.
- Data Processing Agreement: available for every customer — see our DPA.
- Infrastructure: Taskpend runs on certified infrastructure — Supabase (SOC 2 Type II) and AWS (SOC 2, ISO 27001). Taskpend itself is not yet independently certified.
Sub-processors
The companies that process data on our behalf, and when:
| Sub-processor | Purpose | When |
|---|---|---|
| Supabase (on AWS) | Database, authentication, file storage and backend functions | Always |
| Cloudflare | Content delivery, DNS and TLS | Always |
| Lovable | Web app hosting, AI gateway and transactional email delivery | Always |
| Anthropic | AI models that power agents and assistants | When you use AI features |
| Paddle | Payments and billing (merchant of record) | Paid plans |
| Amplitude | Product analytics and session replay | Always |
| Tavily, Exa | Web search for research tasks (search queries only) | When an agent searches the web |
| OpenRouter | AI routing with your own API key | Only if you connect it |
| Google, Slack, Atlassian, GitHub | The integrations you choose to connect | Only if you connect them |
We will update this list before adding a new sub-processor.
Report a vulnerability
If you believe you have found a security issue, email support@taskpend.com with the subject "Security report". We will acknowledge it, investigate, and keep you updated. Please give us reasonable time to fix it before any public disclosure.