Security & Trust

Last updated: September 25, 2026

Taskpend holds your team's tasks, documents and the work your AI agents do on them. This page states plainly how that data is protected. Questions, or a security review to complete? Write to support@taskpend.com.

Encryption

  • In transit: all traffic to Taskpend and its API is encrypted with TLS (HTTPS). Plain HTTP is redirected to HTTPS, and HTTP Strict Transport Security (HSTS) is enforced for one year, including subdomains.
  • At rest: your data is stored in a managed PostgreSQL database run by Supabase on Amazon Web Services, encrypted at rest with AES-256.

Accounts and access

  • Sign-in: email and password, or Sign in with Google (OAuth). Passwords are hashed by our authentication provider and never stored in plain text.
  • Multi-factor authentication: coming soon.
  • Workspace isolation: workspace data is protected by row-level security in the database, so a request can only reach data in the workspace of the person making it.
  • Personal sources stay personal: a mailbox, calendar or Drive is only ever read through the connection of the person who connected it — never through a colleague's.

Connected tools

  • Integrations (Google, Slack, Jira, GitHub) are connected by OAuth, with your explicit consent on the provider's own screen.
  • Access tokens are kept server-side only. They are never sent to the browser and cannot be read by other members of your workspace.
  • You can disconnect any integration at any time from Settings → Connectors.

AI and your data

  • Your data is not used to train AI models. We don't train on it, and our primary AI provider, Anthropic, does not train on data sent through its commercial API.
  • Agents work only on what you ask them to, inside your workspace, and never take irreversible actions. Code changes arrive as pull requests that you review and merge yourself; in a conversation, documents and task changes are shown for review before they are saved.

Your data, your control

  • You own the content you create. We process it only to provide the service.
  • When you delete your account, we delete or anonymize your data within 30 days, unless the law requires us to keep it.
  • You can ask us for a copy of your data, or to correct or delete it, at privacy@taskpend.com.

Compliance

  • GDPR: we process personal data in line with the GDPR — see our Privacy Policy.
  • Data Processing Agreement: available for every customer — see our DPA.
  • Infrastructure: Taskpend runs on certified infrastructure — Supabase (SOC 2 Type II) and AWS (SOC 2, ISO 27001). Taskpend itself is not yet independently certified.

Sub-processors

The companies that process data on our behalf, and when:

Sub-processorPurposeWhen
Supabase (on AWS)Database, authentication, file storage and backend functionsAlways
CloudflareContent delivery, DNS and TLSAlways
LovableWeb app hosting, AI gateway and transactional email deliveryAlways
AnthropicAI models that power agents and assistantsWhen you use AI features
PaddlePayments and billing (merchant of record)Paid plans
AmplitudeProduct analytics and session replayAlways
Tavily, ExaWeb search for research tasks (search queries only)When an agent searches the web
OpenRouterAI routing with your own API keyOnly if you connect it
Google, Slack, Atlassian, GitHubThe integrations you choose to connectOnly if you connect them

We will update this list before adding a new sub-processor.

Report a vulnerability

If you believe you have found a security issue, email support@taskpend.com with the subject "Security report". We will acknowledge it, investigate, and keep you updated. Please give us reasonable time to fix it before any public disclosure.