TaskMatch.ai
Security

How TaskMatch protectsyour data and your work.

How we secure infrastructure, encryption, identity, APIs, and the data lifecycle — with controls documented so technical and procurement reviewers can assess them directly.

Last updated: March 1, 2026

Security architecture overview

Client layer
Gateway controls
Core services
Data layer
Agent boundary

Infrastructure security

Execution environments are isolated, services are segmented, and internal boundaries are treated as part of the security design rather than an implementation footnote.

Encryption posture

Encryption is applied as a layered model: TLS in transit, encryption at rest for stored data, and dedicated handling for sensitive secrets and credentials.

Identity and access

Authentication, token handling, and role scoping are enforced as durable platform controls, so access maps to role and least privilege.

API and boundary defense

Rate limiting, input validation, webhook signature verification, and strict endpoint contracts defend the platform boundary against abuse.

Data lifecycle

Storage, retention, and deletion follow documented lifecycles, and state transitions are recorded so data handling stays auditable.

SOC 2 & compliance

TaskMatch designs its controls around the SOC 2 Type II framework. No audit has been completed to date, and formal certification is an objective on our roadmap rather than a status we hold. The platform is GDPR / RGPD-aligned, and a Data Processing Agreement (DPA) and our control documentation are available to enterprise reviewers on request.

Sensitive data in briefs

Briefs and uploaded documents are encrypted at rest, scoped to the assigned executor for the duration of a task, and excluded from any model-training use. Clients can request redaction or deletion of submitted material.

Security review checklist

How are secrets issued, stored, and rotated?
What isolation exists between services and execution environments?
How are webhook calls authenticated and verified?
What records exist for auditing, incident response, and operational review?
Where does SOC 2 certification stand, and is a DPA available for GDPR / RGPD compliance?
How is sensitive data in briefs and uploads handled, retained, and deleted?

Reviewing TaskMatch for security?

Read the documentation for architecture detail, or contact us for a security review, questionnaire responses, or a walkthrough of our controls.