Security

Overview

Neotask security ko core principle ke roop mein banaaya gaya hai. License activation se lekar data storage aur network communication tak -- har layer aapke data ki suraksha aur unauthorized access ko rokne ke liye design ki gayi hai.

License Security

Two-Factor Authentication (TOTP)

Neotask dashboard access ke liye optional (lekin recommended) two-factor authentication support karta hai.

Encryption

Data at Rest

Data in Transit

Environment Secrets

Desktop App Security

Electron Hardening

Neotask desktop application ki suraksha ke liye strict Electron security settings laagu karta hai:

Content Security Policy (CSP)

App Integrity

Network Security

Gateway Isolation

3-Strike Lockout

API Security

Authentication Methods

Method Used For Security Level
JWT Bearer Token Web dashboard, API calls Standard (90-day expiry)
License HMAC Desktop app operations High (per-device secret)
Session Grants Gateway operations Very High (10-min, HMAC-signed)
TOTP Dashboard login Additional factor

Rate Limiting

Endpoint Limit
Contact form 15 minutes mein 5 requests
Login attempts 15 minutes mein 10 requests
Analytics/tracking 60 seconds mein 30 requests

Input Validation

Provider Key Security (BYOK)

Bring Your Own Key (BYOK) mode use karte waqt, Neotask aapki API keys par additional safeguards laagu karta hai:

Safe Mode

Neotask mein Safe Mode feature hai jo agents ke liye execution sandbox pradaan karta hai:

Audit aur Compliance

Best Practices

  1. Two-factor authentication ke liye apne dashboard par TOTP enable karein.
  2. Backup codes download karein aur unhe securely store karein.
  3. Unexpected charges rokne ke liye daily budgets set karein.
  4. Apni API keys par poora control chahte hain toh BYOK mode use karein.
  5. App updated rakhein, kyunki auto-updates mein security patches shamil hain.
  6. Safe Mode settings mein periodically agent permissions review karein.