Trust & Security
Last updated June 11, 2026
Neotask runs autonomous AI agents for your business, which means it handles data you care about. This page explains, plainly, how we protect it — and exactly what we do and do not claim about our compliance posture.
Compliance posture
- SOC 2 (Type I) — Our control environment is implemented against the SOC 2 Trust Services Criteria across all five categories: Security, Availability, Confidentiality, Privacy, and Processing Integrity, with an append-only internal evidence ledger maintained continuously as controls change.
- GDPR — We process personal data in accordance with the GDPR: records of processing, lawful-basis mapping, a documented retention schedule, self-service data export and erasure, consent-gated analytics that honor GPC/DNT, and Standard Contractual Clauses / Data Privacy Framework safeguards for international transfers. (There is no such thing as a “GDPR certification” — anyone claiming one is overselling.)
- ISO/IEC 27001:2022 — We operate an Information Security Management System aligned to ISO/IEC 27001:2022, including a Statement of Applicability across all 93 Annex A controls, a maintained risk register, and internal audits.
- HIPAA — For healthcare customers, Neotask is HIPAA-aligned as a Business Associate and offers a Business Associate Agreement (BAA). PHI is handled only under a signed BAA, only within a dedicated U.S.-region HIPAA-eligible environment, with AI processing routed exclusively to BAA-covered model providers with zero data retention. HIPAA has no certification; we make no “HIPAA certified” claim. Contact [email protected].
Security architecture
- Encryption in transit — TLS for all connections; API requests are HMAC-SHA256 signed with nonce + timestamp and timing-safe verification.
- Encryption at rest — API keys, OAuth tokens, and secrets are encrypted with AES-256-GCM under a versioned keyring with backward-compatible rotation. The desktop app seals locally cached credentials with your OS keystore (macOS Keychain, Windows Credential Manager, Linux libsecret).
- Local-first gateway — The desktop agent gateway binds to loopback (127.0.0.1) only. It has no external network exposure.
- Tamper-evident records — Billing and audit ledgers are append-only with hash-chained entries; money movements are transactional and idempotent.
- Privacy-safe telemetry — Error monitoring ships no PII by default (redaction on,
sendDefaultPii: false); analytics IPs are anonymized before storage; analytics load only with consent where required. - Human-in-the-loop — Consequential agent actions are gated behind an explicit human approval step before they execute.
Your data, your controls
- Export — Download a complete machine-readable copy of your data, self-service, from account settings.
- Erasure — Delete your account in-app; the deletion cascade covers every tenant-keyed record, revokes connected OAuth tokens, removes stored files, and cancels payment-processor records.
- No training on your content — We do not use your content to train our own models, and we never sell it. AI providers process your content under their API terms; you choose which providers your agents use, including bring-your-own-key.
Transparency
- Live service health — neotask.ai/status
- Subprocessors — neotask.ai/subprocessors, updated whenever the list changes.
- Privacy Policy — neotask.ai/privacy-policy · Cookie Policy — neotask.ai/cookies
- DPA / BAA / security questionnaires — [email protected]
- Vulnerability reports — [email protected]; we ask for responsible disclosure and respond promptly.