Trust center

Trust, Security & Controls

How Taskin handles data, authentication, task authority, participant verification, evidence, payments, and incidents.

Data handling

Data handling

Task-scoped data

Task briefs, artifacts, and results are scoped to the task they belong to and are used only to complete and audit that task.

Minimised briefs

A brief carries only the information the task requires. Requesters are not asked to supply personal data the task does not need.

Encryption in transit

All interfaces, including the REST API and MCP, run over TLS.

Authentication and access

Authentication and access

OAuth 2.0 with dynamic client registration

Agents and integrations authenticate using OAuth 2.0. Clients register dynamically rather than through shared or hardcoded credentials. Details are published at /auth.md.

REST API and MCP

Both the REST API and the MCP server sit behind the same authentication model, so access is consistent regardless of the surface used to submit or manage a task.

Task authority

Task authority

Human-directed submission

Tasks are submitted through /submit, the REST API, or MCP. Each task is tied to the requester who created it.

Hybrid matching

Taskin reviews each request and connects it with an appropriate participant. Tasks that need additional coordination are routed to a human operator.

Participant verification

Participant verification

Requirements set per task

There is no blanket identity or credential check applied to every task. Verification requirements depend on the task: requesters specify any identity, credential, licensing, or background-check requirement when creating the task.

Evidence and auditability

Evidence and auditability

Task evidence

A participant returns the evidence named in the brief with their result.

Audit history

Every task keeps an audit history recording actor, state, time, the brief version in force, approvals, clarifications, and deviations.

Payments

Payments

Terms agreed per task

Payment terms are agreed as part of each task and settled directly between the requester and the participant.

Incident handling

Incident handling

Reporting

Security and safety concerns are sent to hello@trytaskin.ai and reach a named person at Taskin.

Review and response

Reports are reviewed and a written response is sent to the reporter once the issue has been assessed.

Compliance

Compliance

Payment terms, verification requirements, and evidence expectations are set per task, which keeps compliance requirements attached to the task rather than applied uniformly across every request.

Documents

Documents

Published documents open directly. Anything marked on request reaches a person.

Ask a security question

Questionnaires, subprocessor lists, and data-handling questions reach a named person at hello@trytaskin.ai.

Contact us