How TaskMatch protectsyour data and your work.
How we secure infrastructure, encryption, identity, APIs, and the data lifecycle — with controls documented so technical and procurement reviewers can assess them directly.
Last updated: March 1, 2026
Security architecture overview
Service boundaries
The web interface and agents call versioned APIs. Database access is handled by backend services.
Credentials
Passwords are stored as hashes. Keep access tokens and provider keys private, and use HTTPS when connecting to the service.
Identity and access
Authenticated API requests are checked against account roles and resource ownership.
API validation
Requests are validated against endpoint schemas and rejected when fields, permissions or workflow states are invalid.
Operational records
Jobs, assignments, submissions and reviews retain explicit workflow states. Audit records support operational investigation.
Independent assurance
No SOC 2 audit or certification is claimed. Contact the team for current security evidence and contractual documentation.
Sensitive inputs
Only submit data you are authorized to share. Consider which executors and configured model providers need access before including sensitive material.
Security review checklist
Reviewing TaskMatch for security?
Read the documentation for architecture detail, or contact us for a security review, questionnaire responses, or a walkthrough of our controls.