SECURITY / 09

Practical controls at every boundary.

Security begins with narrow, testable boundaries: where identity is verified, which tenant owns a row, how a file path is authorized and which code is allowed to hold a secret.

IMPLEMENTED FOUNDATIONS

Controls described at the level they actually exist.

These statements reflect the reviewed application foundation already present in the product. They are not certification claims or substitutes for launch policy.

  1. 01

    SECRETS

    Privileged credentials are read through server-only modules and are never exposed through browser-prefixed configuration.

    IMPLEMENTED
  2. 02

    ACTORS

    Authenticated users are resolved from verified claims. Administrative capability comes from a server-controlled allowlist rather than a user-editable profile flag.

    IMPLEMENTED
  3. 03

    TENANTS

    Organization data uses row-level security, constrained helper functions and exact grants so access follows verified membership.

    IMPLEMENTED
  4. 04

    STORAGE

    Organization files live in private, path-constrained storage. Authorized downloads use short-lived signed URLs after membership is checked.

    IMPLEMENTED
  5. 05

    INVITES

    Invitation tokens are server-mixed, stored as hashes, expire and are single-use. Acceptance is tied to the confirmed authenticated identity.

    IMPLEMENTED
  6. 06

    AUDIT

    An append-only audit foundation records sensitive system actions through a constrained server path rather than client-writable rows.

    IMPLEMENTED

ENGINEERING PRACTICE

Safe delivery continues beyond the application boundary.

Scoped access

Use provider-native invitations and least-privilege roles. Do not send credentials, private keys or access tokens in request text.

Human review

Architecture, permissions, sensitive changes, tests and release decisions remain subject to human review.

Client control

Source repositories, infrastructure and provider accounts normally remain owned by the client and governed by their controls.

LAUNCH DISCLOSURES

Unknown policy is not a promise.

CertificationNo certification is claimed on this page.

RetentionA retention guarantee is not published until the production policy and deletion flows are configured and verified.

SubprocessorsA named subprocessor list is not inferred from code or planned integrations; it must reflect the production configuration.

Security contactReports reach info@tasktoprod.com, which is monitored.

REPORTING

Report a vulnerability to info@tasktoprod.com.

Include the affected URL and the steps to reproduce. Reports reach the operator directly rather than a queue. Please do not run automated scans against production or access data that is not yours. No response time is promised here, and this is not a paid disclosure programme.

NEXT / INTAKE

Start with the task. Keep sensitive access in the system that owns it.

Send the outcome, the context you have and what done should look like. The first response stays written and practical.

Send a task first →

No sales call. No commitment.