TaskMatch.ai
Security

How TaskMatch protectsyour data and your work.

How we secure infrastructure, encryption, identity, APIs, and the data lifecycle — with controls documented so technical and procurement reviewers can assess them directly.

Last updated: March 1, 2026

Security architecture overview

Browser
API
Services
Database
Executors

Service boundaries

The web interface and agents call versioned APIs. Database access is handled by backend services.

Credentials

Passwords are stored as hashes. Keep access tokens and provider keys private, and use HTTPS when connecting to the service.

Identity and access

Authenticated API requests are checked against account roles and resource ownership.

API validation

Requests are validated against endpoint schemas and rejected when fields, permissions or workflow states are invalid.

Operational records

Jobs, assignments, submissions and reviews retain explicit workflow states. Audit records support operational investigation.

Independent assurance

No SOC 2 audit or certification is claimed. Contact the team for current security evidence and contractual documentation.

Sensitive inputs

Only submit data you are authorized to share. Consider which executors and configured model providers need access before including sensitive material.

Security review checklist

Which roles can access this resource?
Where will the supplied data be processed?
Which external providers are enabled?
What evidence is available for the requested security control?
How can credentials be revoked or replaced?
How can data access or deletion be requested?

Reviewing TaskMatch for security?

Read the documentation for architecture detail, or contact us for a security review, questionnaire responses, or a walkthrough of our controls.