← Back to home

Trust & Security

Last updated June 11, 2026

Neotask runs autonomous AI agents for your business, which means it handles data you care about. This page explains, plainly, how we protect it — and exactly what we do and do not claim about our compliance posture.

Compliance posture

  • SOC 2 (Type I) — Our control environment is implemented against the SOC 2 Trust Services Criteria across all five categories: Security, Availability, Confidentiality, Privacy, and Processing Integrity, with an append-only internal evidence ledger maintained continuously as controls change.
  • GDPR — We process personal data in accordance with the GDPR: records of processing, lawful-basis mapping, a documented retention schedule, self-service data export and erasure, consent-gated analytics that honor GPC/DNT, and Standard Contractual Clauses / Data Privacy Framework safeguards for international transfers. (There is no such thing as a “GDPR certification” — anyone claiming one is overselling.)
  • ISO/IEC 27001:2022 — We operate an Information Security Management System aligned to ISO/IEC 27001:2022, including a Statement of Applicability across all 93 Annex A controls, a maintained risk register, and internal audits.
  • HIPAA — For healthcare customers, Neotask is HIPAA-aligned as a Business Associate and offers a Business Associate Agreement (BAA). PHI is handled only under a signed BAA, only within a dedicated U.S.-region HIPAA-eligible environment, with AI processing routed exclusively to BAA-covered model providers with zero data retention. HIPAA has no certification; we make no “HIPAA certified” claim. Contact [email protected].

Security architecture

  • Encryption in transit — TLS for all connections; API requests are HMAC-SHA256 signed with nonce + timestamp and timing-safe verification.
  • Encryption at rest — API keys, OAuth tokens, and secrets are encrypted with AES-256-GCM under a versioned keyring with backward-compatible rotation. The desktop app seals locally cached credentials with your OS keystore (macOS Keychain, Windows Credential Manager, Linux libsecret).
  • Local-first gateway — The desktop agent gateway binds to loopback (127.0.0.1) only. It has no external network exposure.
  • Tamper-evident records — Billing and audit ledgers are append-only with hash-chained entries; money movements are transactional and idempotent.
  • Privacy-safe telemetry — Error monitoring ships no PII by default (redaction on, sendDefaultPii: false); analytics IPs are anonymized before storage; analytics load only with consent where required.
  • Human-in-the-loop — Consequential agent actions are gated behind an explicit human approval step before they execute.

Your data, your controls

  • Export — Download a complete machine-readable copy of your data, self-service, from account settings.
  • Erasure — Delete your account in-app; the deletion cascade covers every tenant-keyed record, revokes connected OAuth tokens, removes stored files, and cancels payment-processor records.
  • No training on your content — We do not use your content to train our own models, and we never sell it. AI providers process your content under their API terms; you choose which providers your agents use, including bring-your-own-key.

Transparency