Signing in
You can sign in with Google, with Microsoft, or with an email address and
a one-time code. Social sign-in verifies the provider's token on our
server — against Google's token endpoint, and against Microsoft's public
signing keys — rather than trusting anything the browser sends us.
Where your data sits
Application data is stored in a PostgreSQL database. Uploaded files are
stored on the application's own storage. We do not sell data, we do not
use it to train anything, and we do not share it with third parties
except the infrastructure providers needed to run the service.
Payments
Card details never reach our servers. Payment is handled by a payment
provider, and our database holds only a subscription period and a
reference issued by that provider. There is nothing card-shaped in it to
steal.
What we have not done yet
Being straight about this is more useful to a reviewer than a page of
badges:
- No SOC 2 or ISO 27001 certification.
- No independent penetration test yet.
- Single-region hosting; no data residency choice.
- Two-factor authentication beyond the email code is not available yet.
Reporting something
If you find a vulnerability, email
security@worktaskme.com with
enough detail to reproduce it. We will confirm receipt within three
working days. Please give us a reasonable window to fix it before
publishing, and do not access data that is not yours while testing.