Legal Center

Security at Taskologic

Last updated: July 24, 2026

Taskologic is designed to keep company work separated, access controlled, and important actions accountable.


How we protect your workspace

Workspace-bound access

Projects, tasks, documents, conversations, reminders, meeting context, and integrations are associated with a specific workspace. Requests are authenticated and checked against workspace membership before protected data is returned.

Roles and permissions

Workspace owners and admins manage membership and elevated controls. Project access and administrative actions are restricted according to the user’s role and the workspace context.

Protected files

Document attachments are accessed through authenticated application flows. Private file access uses short-lived signed links where supported, limiting how long a file URL remains usable.

Authentication and credentials

Passwords are stored using one-way hashing. Authenticated sessions use signed tokens, and sensitive routes require authorization checks.

Connected-app credentials and provider tokens are encrypted before storage. Taskologic does not display provider secrets to workspace users or include raw access tokens in integration audit records.

Integrations

Taskologic uses scoped authorization for connected services. Each customer workspace approves its own connection, requested permissions, and provider account.

OAuth connection flows use expiring, one-time state records. Taskologic MCP connections add workspace-bound authorization, audience validation, scope enforcement, token revocation, and refresh-token rotation.

Workspace admins can review connected applications, granted scopes, recent use, and revocation controls from Integrations.

AI and automated actions

TIA and Taskologic agents operate within workspace and plan permissions. Actions that can materially change work are designed to remain visible and may require human approval before they are applied.

Workspace AI controls support approved providers and organization-level configuration. AI output should still be reviewed before it is used for consequential decisions.

Monitoring and accountability

Taskologic records security-relevant administrative, integration, billing, and automation activity where supported. Rate limits protect sensitive authentication, integration, and operational endpoints from excessive use.

We investigate suspected security incidents and notify affected customers when required by applicable law or contractual commitments.

Infrastructure and service providers

Taskologic uses established infrastructure providers for application hosting, storage, communications, payments, meetings, and AI processing. Data is protected in transit using HTTPS where supported by the service path, with additional safeguards provided by the underlying vendors.

Third-party services connected by a customer remain subject to that provider’s security, privacy, and availability practices.

Current compliance posture

Taskologic maintains security, privacy, AI disclosure, acceptable-use, recording-consent, and data-processing documentation. Formal certifications and additional enterprise controls are tracked separately in our Compliance Roadmap.

Taskologic does not currently represent itself as SOC 2 certified.

Your role

Customers are responsible for managing workspace membership, selecting appropriate integrations, protecting account credentials, reviewing granted permissions, and obtaining required consent before recording or processing meetings.

Report unexpected access, suspected misuse, or a security concern as soon as possible.

Contact

Security inquiries and responsible disclosures: support@taskologic.com

Privacy requests: support@taskologic.com