Last Updated: April 17, 2026
๐ Our Security Commitments
๐
Encryption in Transit
All data encrypted using TLS/SSL
โ๏ธ
Secure Cloud Hosting
Hosted on Render (SOC 2)
๐
Access Controls
Role-based permissions
๐
Regular Audits
Security reviews & updates
1. Data Protection
We implement industry-standard security measures to protect your data:
- Encryption: All data in transit is encrypted using TLS 1.2+
- Secure Infrastructure: Hosted on Render's secure, SOC 2 compliant infrastructure
- Access Controls: Role-based access and authentication required for all data access
- Regular Updates: We maintain up-to-date dependencies and security patches
2. Payment Security
All payment processing uses PCI-compliant third-party providers:
- We do NOT store credit card information
- Payments processed through Stripe/PayPal
- All transactions encrypted end-to-end
- PCI DSS Level 1 compliant providers
3. User Authentication
Account security features:
- Secure session management
- Password requirements enforced
- Optional two-factor authentication (coming soon)
- Automatic session timeout after inactivity
4. AI API Key Security
When you provide your own API keys for AI features:
- Client-Side Only: Keys are processed in your browser, never sent to our servers
- Local Storage: Keys stored locally on your device only
- No Server Access: We never see or store your AI API keys
- You Control: You can clear keys anytime from browser settings
5. Third-Party Integrations
When connecting Google, Notion, Slack, GitHub:
- Only necessary permissions are requested
- OAuth tokens are encrypted and stored securely
- You can disconnect integrations anytime
- We follow OAuth 2.0 best practices
6. Data Backup & Recovery
- Regular automated backups (multiple times daily)
- Encrypted backup storage
- Disaster recovery plan in place
- Recovery point objective (RPO): 24 hours
7. Incident Response
In case of a security incident:
- 24-hour initial assessment
- Affected users notified within 72 hours
- Incident report published if required
- Remediation plan implemented
8. Employee Access
Our team follows strict access protocols:
- Least privilege access principle
- Background checks for employees
- Access logging and auditing
- Immediate access revocation on termination
9. Security Best Practices
We recommend you also:
- Use a strong, unique password
- Enable two-factor authentication when available
- Don't share your account credentials
- Keep your email and recovery options updated
- Review connected integrations periodically
- Log out of shared devices
10. Vulnerability Reporting
We welcome responsible security research. If you discover a vulnerability:
โ ๏ธ Do NOT exploit vulnerabilities.
Report to [email protected] instead. We will:
- Acknowledge reports within 24 hours
- Provide timeline for remediation
- Acknowledge your contribution (with permission)
11. Compliance
We are working toward compliance with:
- GDPR (General Data Protection Regulation) โ EU
- CCPA (California Consumer Privacy Act) โ USA
- SOC 2 Type II โ Security standards
Our privacy policy compliance details are in our Privacy Policy.
12. Contact Information
For security questions or to report vulnerabilities:
Security Email: [email protected]
General Support: [email protected]
Website: https://mrtaskflow.site