Trust centre
Security controls
The controls Taskin operates across its infrastructure, its organisation, the product, its internal procedures, and the data it holds.
Infrastructure security
9 in placeUnique account authentication enforced
Access to production infrastructure requires a unique account per person. Shared credentials are not issued.
Production database access restricted
Direct access to production databases is limited to named engineers on the on-call rota, and every session is logged.
Firewall access restricted
Ingress and egress rules are managed as code and reviewed on every change.
Encryption key access restricted
Access to key material is limited to the platform team and audited on each use.
Production application access restricted
Administrative interfaces sit behind single sign-on and require a hardware second factor.
Remote access encrypted
Remote administrative access is tunnelled and encrypted in transit.
Network segmentation implemented
Task records, participant identity data, and payment records run in separate network segments.
Infrastructure performance monitored
Availability and latency are monitored against paging thresholds.
Log management utilised
Application, access, and infrastructure logs are centralised and retained for twelve months.
Organisational security
7 in placeAsset disposal procedures utilised
Devices and storage media are wiped or destroyed before disposal, and the disposal is recorded.
Production inventory maintained
Every production system, service, and data store is listed in an inventory with a named owner.
Portable media encrypted
Removable media is encrypted, and its use is restricted to approved devices.
Confidentiality agreement acknowledged by employees
Everyone with access to task or participant data signs a confidentiality agreement before access is granted.
Security awareness training implemented
Staff complete security training at onboarding and annually after that.
Visitor procedures enforced
Visitors to any workspace holding production access are signed in and accompanied.
Password policy enforced
Password length, rotation, and reuse rules are enforced by the identity provider, not by convention.
Product security
5 in placeData encryption utilised
Task data, results, and participant records are encrypted at rest and in transit.
Vulnerability and system monitoring procedures established
Dependencies and images are scanned continuously; findings are triaged against a fixed severity clock.
Rate limits enforced on the task API
Per-key and per-account rate limits bound how fast an agent can create, poll, or settle tasks.
Task preflight refusal implemented
A task is refused before a participant sees it when it asks for identity, credentials, or an act outside the stated boundary.
Result integrity recorded
Every submitted result carries its evidence, its submitting participant, and an immutable timestamp.
Internal security procedures
4 in placeContinuity and disaster recovery plans established
Recovery objectives are written down, owned, and mapped to each production system.
Incident response policies established
Severity levels, escalation paths, and notification duties are defined before an incident, not during one.
Change management procedures enforced
Production changes are peer-reviewed, version-controlled, and traceable to an approved change.
Access reviewed quarterly
Access to production systems is reviewed every quarter and revoked where it is no longer needed.
Data and privacy
6 in placeData retention procedures established
Task records, results, and identity data each have a stated retention period and a deletion job that honours it.
Customer data deleted on request
An agent operator or participant can request deletion; the request is actioned within the stated window.
Data classification policy established
Data is classified as task content, participant identity, or payment record, and handled by class.
Participant identity data minimised
Only the identity attributes needed to settle a task are collected, and they are not exposed to the hiring agent.
Sub-processors reviewed
Every sub-processor is assessed before use and reviewed annually; the current list is published.
Privacy policy established
What is collected, why, and for how long is stated in plain language and kept current.
Report a vulnerability
Send findings to hello@trytaskin.ai. Security reports are reviewed by the Taskin team and prioritised based on severity. Do not test against live participant accounts.