Security & trust

You are handing us your team’s location, hours and pay.

That deserves more than a badge on a landing page. Here is precisely how TaskBit is built, what we hold, and what we have not done yet.

Encrypted end to end in transit

Every request runs over TLS 1.2+ with HSTS enforced. Certificates are managed and rotated by the platform, not by hand.

Encrypted at rest

Database and backup volumes are encrypted at rest. Particularly sensitive fields — bank details among them — are encrypted at the application layer as well.

Per-organisation isolation

Every query is scoped to the caller’s organisation by an attribute-based access control layer, and cross-tenant access is covered by negative tests, not just by review.

Hardened authentication

JWT access tokens with rotating refresh tokens, two-factor authentication, login rate limiting, lockout after repeated failures, and session revocation from any device.

Device-level protection

The staff app locks behind Face ID, Touch ID or a PIN, so a borrowed or lost phone does not expose a payslip.

Audit logging

Sensitive actions — rota publishing, pay runs, permission changes, data exports — are written to an append-only audit log visible to your admins.

Backups & recovery

Automated database backups with point-in-time recovery. Restores are tested, not assumed.

Data residency

Data is hosted in the UK/EU by default. Enterprise customers can agree a specific region contractually.

Data-subject rights

GDPR export and delete are built into the product, so a subject-access request is a task, not a project.

Access control

People see their own work — and nothing else.

Permissions follow the org chart rather than a flat "admin or not" switch. A frontline employee sees their shifts, their pay and their documents. A manager sees only the locations they run. An agency's client contact sees only their own placements, on an allowlist that new internal screens can never accidentally join.

  • Role and attribute-based access control enforced in the API, not the interface
  • Back-office sections hidden from frontline staff by group, so new screens are private by default
  • External client accounts built from an allowlist, not by subtraction
  • Every denial is a server-side 403 — hiding a menu item is never the control
Reporting a vulnerability

Write to security@taskbithr.com with steps to reproduce. We will acknowledge within one working day, keep you updated, and credit you if you would like. Please give us a reasonable window to fix the issue before publishing.

What we have not done yet

We are not currently ISO 27001 or SOC 2 certified, and we will not imply otherwise. We complete security questionnaires, provide our architecture and sub-processor detail, and sign a DPA. If a formal certification is a hard requirement for you, tell us — it affects our roadmap.

Operations

How we run it day to day.

Monitoring

Structured request logging, error monitoring and uptime alerting on the API and the web app.

Change management

Every change goes through review, automated tests and a staged deploy. Migrations are additive and never edited once applied.

Incident response

A named owner, a written timeline, and customer notification without undue delay where a breach affects personal data.

Sub-processors

Hosting, database, email, payments, error monitoring and push delivery are named publicly, with notice before we add one.

Full list: sub-processors · privacy policy · data processing agreement

Security FAQ

What procurement always asks.

Do you sign a DPA?

Yes. Our standard data processing agreement is published in full and covers TaskBit acting as processor for your employee data. We can execute it as a signed document on request.

Where is our data hosted?

UK/EU regions by default. The specific hosting and database providers are named on the sub-processors page.

Do you collect employee location?

Only at the moment of a clock-in or clock-out, and only to confirm the punch happened inside your geofence. We do not track staff between punches, and we say so in the privacy policy.

Can we use single sign-on?

SSO is available on the Enterprise plan. Everyone else gets two-factor authentication and enforced password policies.

How do we get our data out?

Exports are available from the product at any time, and GDPR export covers a named individual’s full record. There is no exit fee and no hostage period.

What happens to our data if we leave?

It is retained for a short, defined window so an accidental cancellation can be reversed, then deleted. The window and the process are set out in the terms.

Send us your security questionnaire.

We will complete it properly rather than pointing you at a trust page and hoping.

No credit card. Cancel any time. Or book a demo instead.