Data protection
- AES-256 encryption at rest, TLS 1.3 in transit
- Field-level encryption for location and personal identifiers
- Data residency in India, with regional options on Enterprise
- Configurable retention — location traces default to 90 days
Security & compliance
Location, rosters and travel patterns are sensitive personal data. Our controls, certifications and retention policy are built for the scrutiny that deserves.
Certified
ISO/IEC 27001:2022
Information security management system certified and under surveillance. Certificate 520F6AED, valid to 11 September 2029.
Aligned, not certified
SOC 2
Our controls are designed and operated against the AICPA Trust Services Criteria for Security and Availability. We have not completed a SOC 2 audit and do not hold a SOC 2 report — independent assurance of these controls is provided today by our ISO/IEC 27001 certification.
Compliant
GDPR & DPDP
Aligned to EU GDPR and India’s Digital Personal Data Protection Act, with a DPA and sub-processor list available on request.
Accredited
IATA
Accredited agency for air content in the Corporate Travel module.
Reliability
Availability is engineered as a safety requirement, with a manned control room behind the software.
Primary storage and processing are in India. Enterprise customers can request specific regional hosting where a global policy requires it.
Live location is retained for 90 days by default, then aggregated. Retention windows are configurable per customer contract.
Yes. The app shows when tracking is active — during a trip window only — and what the transport desk can see.
Vendors receive only what is needed to fulfil a trip: pickup, drop, timing and contact details for that trip. Nothing else is exposed.
Yes. We provide our ISO 27001 certificate, our in-house VAPT summaries and a completed customer security questionnaire under NDA. Our penetration testing is conducted by our own security team rather than a third-party assessor.
Security documentation
Our ISO 27001 certificate, in-house VAPT summaries and DPA templates are available under NDA. Vulnerability reports go to security@taski.in.
Hi there. How can we help?
Real people, Monday to Saturday