Trust & Security

Product Controls

Use Settings → Privacy and Data for data choices, Settings → Permissions for Safe Mode, and Approvals for actions waiting on review.

Session data sharing control, off by default

How Neotask protects your data. This page summarizes our security posture for customers and prospects. For our formal compliance status and how to request audit reports, see Compliance Overview. For data-protection rights, see Data Privacy & Your Rights.

Our security principles

Data protection

Area What we do
Encryption in transit All API and gateway traffic uses TLS. Plaintext transport is refused.
Encryption at rest AES-256-GCM field-level encryption for credentials, OAuth tokens, provider keys, and other sensitive records, with versioned keys and backward-compatible key rotation.
Access control Token-based authentication, role-based access within an account, and HMAC-signed requests (nonce + timestamp) for device and service calls.
Secrets management No hardcoded secrets; production secrets are required at startup (the service fails closed if a required secret is missing) and are never logged.
Audit logging Privileged and security-relevant actions are recorded to an append-only, tamper-evident audit log.
Monitoring Error and availability monitoring with health checks and alerting; personal data is excluded from telemetry by default.

Infrastructure & hosting

Secure development

Safe Mode requires an explicit confirmation before broader machine access is enabled.

Safe Mode confirmation

AI processing

Neotask routes AI requests through our gateway to model providers (see the Subprocessors list). We minimize what is sent, do not use your private content to train our own models, and document the providers that may process prompt content so you can make an informed choice.

Reporting a security issue

If you believe you've found a vulnerability, contact [email protected]. Please do not publicly disclose it until we've had a chance to investigate and remediate.