Encrypted end to end in transit
Every request runs over TLS 1.2+ with HSTS enforced. Certificates are managed and rotated by the platform, not by hand.
That deserves more than a badge on a landing page. Here is precisely how TaskBit is built, what we hold, and what we have not done yet.
Every request runs over TLS 1.2+ with HSTS enforced. Certificates are managed and rotated by the platform, not by hand.
Database and backup volumes are encrypted at rest. Particularly sensitive fields — bank details among them — are encrypted at the application layer as well.
Every query is scoped to the caller’s organisation by an attribute-based access control layer, and cross-tenant access is covered by negative tests, not just by review.
JWT access tokens with rotating refresh tokens, two-factor authentication, login rate limiting, lockout after repeated failures, and session revocation from any device.
The staff app locks behind Face ID, Touch ID or a PIN, so a borrowed or lost phone does not expose a payslip.
Sensitive actions — rota publishing, pay runs, permission changes, data exports — are written to an append-only audit log visible to your admins.
Automated database backups with point-in-time recovery. Restores are tested, not assumed.
Data is hosted in the UK/EU by default. Enterprise customers can agree a specific region contractually.
GDPR export and delete are built into the product, so a subject-access request is a task, not a project.
Permissions follow the org chart rather than a flat "admin or not" switch. A frontline employee sees their shifts, their pay and their documents. A manager sees only the locations they run. An agency's client contact sees only their own placements, on an allowlist that new internal screens can never accidentally join.
Write to security@taskbithr.com with steps to reproduce. We will acknowledge within one working day, keep you updated, and credit you if you would like. Please give us a reasonable window to fix the issue before publishing.
We are not currently ISO 27001 or SOC 2 certified, and we will not imply otherwise. We complete security questionnaires, provide our architecture and sub-processor detail, and sign a DPA. If a formal certification is a hard requirement for you, tell us — it affects our roadmap.
Structured request logging, error monitoring and uptime alerting on the API and the web app.
Every change goes through review, automated tests and a staged deploy. Migrations are additive and never edited once applied.
A named owner, a written timeline, and customer notification without undue delay where a breach affects personal data.
Hosting, database, email, payments, error monitoring and push delivery are named publicly, with notice before we add one.
Full list: sub-processors · privacy policy · data processing agreement
Yes. Our standard data processing agreement is published in full and covers TaskBit acting as processor for your employee data. We can execute it as a signed document on request.
UK/EU regions by default. The specific hosting and database providers are named on the sub-processors page.
Only at the moment of a clock-in or clock-out, and only to confirm the punch happened inside your geofence. We do not track staff between punches, and we say so in the privacy policy.
SSO is available on the Enterprise plan. Everyone else gets two-factor authentication and enforced password policies.
Exports are available from the product at any time, and GDPR export covers a named individual’s full record. There is no exit fee and no hostage period.
It is retained for a short, defined window so an accidental cancellation can be reversed, then deleted. The window and the process are set out in the terms.
We will complete it properly rather than pointing you at a trust page and hoping.
No credit card. Cancel any time. Or book a demo instead.