Trust

Security

This page describes the security practices Task Machine uses to protect product and website data. It should be read together with our Privacy Policy.

Last updated: 22 June 2026

Infrastructure security

Task Machine runs on managed infrastructure for application hosting, database storage, object storage, email delivery, monitoring, and backups. We keep the setup intentionally small, limit production access, and review infrastructure changes before they affect users.

Public traffic is served over HTTPS, and production access is restricted to the people and systems that need it. Backup and restore checks are part of regular operating practice.

Data in transit

All traffic to taskmachine.io and the application is served over HTTPS using modern TLS. Plaintext requests are redirected to HTTPS.

Data at rest

Application data is stored in Scaleway Managed Database for PostgreSQL. Uploads, generated artifacts, skill bundles, and backup material are stored in Scaleway Object Storage. Access is restricted to the systems and operators that need it, and retention windows are documented.

Access control

Access to production systems and customer data is limited to the people who need it to operate the service. Sessions are carried in signed cookies, and forms are protected against cross-site request forgery.

Inside a workspace, permissions and approval steps let you control who, human or agent, can take which actions and where a human sign-off is required before work continues.

Application security

The application sets secure HTTP headers, including a content security policy, and is kept current with security updates to its framework and dependencies.

Agents, runtimes, and model providers

Task Machine coordinates humans, agents, approvals, and runtimes. Work may be processed by third-party language model and agent providers under their own terms and security practices.

Agent and tool outputs can be incomplete or wrong. Approval steps and verifiers are there so a human or a check can sign off before an output is used or an action is taken.

Compliance and certifications

Task Machine is operated from Spain and processes personal data under the EU General Data Protection Regulation. Details of how we handle personal data are in our Privacy Policy.

Task Machine is an early-stage product in private beta and does not yet hold formal third-party certifications such as SOC 2 or ISO 27001. We will not claim certifications we do not hold. Data processing agreement and subprocessor information is available on request where required.

Incident response

If we become aware of a security incident affecting personal data, we investigate, take steps to contain it, and notify affected users and the competent authorities where the law requires it.

Responsible disclosure

If you believe you have found a security vulnerability, please report it to security@taskmachine.io rather than disclosing it publicly. We will look into valid reports and ask that you give us a reasonable chance to address the issue first.

Contact

For security questions, email security@taskmachine.io . Personal data is handled under the Privacy Policy.