Security & compliance
Your data is yours. We build security into every layer of the platform: from encryption to access controls to audit trails.
Encryption
- Data in transit: All connections use TLS 1.3: the same encryption standard as online banking.
- Data at rest: All stored data is encrypted using AES-256 on encrypted cloud volumes.
- Credentials: Saved credentials are encrypted with Fernet (symmetric) keys managed separately from the data. They are never stored in plain text, logged, or committed to source control.
Credential Handling
- You type credentials directly in the secure portal: they never touch our code or build pipeline.
- Credentials are used once at runtime and discarded unless you choose to save them for recurring automations.
- Saved credentials are encrypted at rest and decrypted only in-memory at execution time.
- We never have access to your raw credentials. They are yours and yours alone.
Infrastructure
- Automations run in isolated cloud environments: not on your network or local machines.
- Infrastructure is hosted on encrypted cloud servers with automatic security patching.
- Each automation runs in a sandboxed execution environment with no cross-tenant data access.
- We do not store or retain your business data beyond what is required to execute your automation.
Audit Trail
- Every automation run is logged with timestamps, input/output summaries, and execution status.
- You can view the complete audit log in the portal at any time.
- Any errors or credential access events are recorded and surfaced in the activity log.
Access Controls
- Portal access is secured with encrypted authentication (JWT tokens + bcrypt hashing).
- You can revoke or rotate credentials at any time: no dependency on us.
- Integrations use OAuth or scoped API keys with the minimum permissions needed for the automation.
- No backdoors. No persistent remote access to your systems.
Data Residency & Compliance
- Your data stays in your chosen region. We do not migrate or replicate data across jurisdictions without your consent.
- We are actively pursuing SOC 2 compliance as we scale. Current security practices align with SOC 2 control framework.
- We sign NDAs and data processing agreements (DPAs) for all client engagements.
Self-Hosted AI Consultancy
For organisations that cannot send data outside their network, we offer a complete self-hosted solution.
We design, deploy and hand over a private AI and automation environment that runs fully inside your infrastructure: whether on your servers, private cloud, or air-gapped network.
You get the same custom, reliable automations TaskSultan is known for, but with complete data sovereignty. We set everything up, train your team, and optionally provide ongoing support. Your data stays yours.
Cloud vs Self-Hosted
| Capability | TaskSultan Cloud | Self-Hosted |
|---|---|---|
| Where it runs | Our secure cloud | Your infrastructure |
| Data residency | Encrypted cloud (choose region) | Fully on-premise, air-gap ready |
| Setup time | 3-7 days | 2-4 weeks (custom deployment) |
| Best for | Most SMBs and mid-market teams | Regulated industries, sensitive data |
| Maintenance | We handle everything | Handover + optional support retainer |
| Team training | N/A | Included |
Have specific security requirements?
We work with enterprise clients who need custom data processing agreements, on-premise deployment options, or detailed security questionnaires. Let’s talk.
Contact us about security