Security & compliance

We hold employee movement data. We treat it that way.

Location, rosters and travel patterns are sensitive personal data. Our controls, certifications and retention policy are built for the scrutiny that deserves.

Controls, by domain.

Data protection

  • AES-256 encryption at rest, TLS 1.3 in transit
  • Field-level encryption for location and personal identifiers
  • Data residency in India, with regional options on Enterprise
  • Configurable retention — location traces default to 90 days

Access control

  • SSO via SAML and OIDC; SCIM provisioning on Enterprise
  • Role-based permissions down to site and cost centre
  • Mandatory MFA for all administrative accounts
  • Just-in-time internal access with full session logging

Application security

  • In-house vulnerability assessment and penetration testing, twice yearly
  • Static and dependency scanning in every build
  • Responsible disclosure programme with published SLAs
  • Segregated production, staging and development environments

Infrastructure

  • Hosted on tier-one cloud infrastructure in India
  • Network isolation with private subnets and bastion access
  • Web application firewall on the OWASP Core Rule Set
  • Encrypted, geo-redundant backups tested quarterly

Operational security

  • Background verification for all employees with data access
  • Annual security training and phishing simulation
  • Documented incident response with defined escalation paths
  • Vendor risk assessment before any partner integration

Privacy by design

  • Employees see what is tracked and when, in the app
  • Location capture limited to active trip windows
  • Purpose limitation enforced in the data model
  • DPA and sub-processor list available on request

Reliability

A transport platform that goes down strands people.

Availability is engineered as a safety requirement, with a manned control room behind the software.

Platform uptime commitment
99.9%
Sev-1 acknowledgement
< 15 min
Manned control room
24 / 7
Recovery point objective
RPO 15 min

Common security questions

Where is our data stored?

Primary storage and processing are in India. Enterprise customers can request specific regional hosting where a global policy requires it.

How long do you keep location data?

Live location is retained for 90 days by default, then aggregated. Retention windows are configurable per customer contract.

Can employees see what is being tracked?

Yes. The app shows when tracking is active — during a trip window only — and what the transport desk can see.

Do you share data with vendors?

Vendors receive only what is needed to fulfil a trip: pickup, drop, timing and contact details for that trip. Nothing else is exposed.

Can we run a security review before signing?

Yes. We provide our ISO 27001 certificate, our in-house VAPT summaries and a completed customer security questionnaire under NDA. Our penetration testing is conducted by our own security team rather than a third-party assessor.

Security documentation

Need our security documentation?

Our ISO 27001 certificate, in-house VAPT summaries and DPA templates are available under NDA. Vulnerability reports go to security@taski.in.