• Phishing IQ
  • Pricing
  • FAQ
securitytask
Sign In
Sign Up
securitytask

Swiss-made gamified security awareness training for SMBs. Turn compliance into a habit your team actually keeps — with NIS2, ISO 27001 & nFADP training evidence.

© Copyright 2026 SecurityTask. All Rights Reserved.

Product
  • Pricing
  • Phishing IQ test
  • FAQ
Get Started
  • Sign In
  • Sign Up
Legal
  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Trust & Security
  • DPA

Trust & Security

How we protect your data — and your people’s.

A summary of our security posture. For personal-data processing, see the Privacy Policy and the Data Processing Agreement (DPA).

Hosting & data residency

Data is hosted in the European Union (Frankfurt, eu-central-1 region) on a managed PostgreSQL database. GDPR-compliant EU hosting; no routine transfer of personal data outside the EU/EEA.

Encryption

Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Credentials are never stored in plaintext.

Tenant isolation

Every organization is isolated at the database layer using PostgreSQL Row-Level Security (RLS): a query can only ever reach its own organization’s data — enforced by the database itself, not just the application.

Tamper-proof evidence

The admin audit log and training records (the compliance evidence) are append-only: the application can only insert and read them, never update or delete. Evidence cannot be altered or erased — not even by an administrator.

Backups & recovery

On the production plan, daily backups with point-in-time recovery (PITR). Evidence is also exportable to PDF/CSV and via the SIEM connector, so you can keep independent copies.

Data retention

Training and compliance evidence (completions, policy acknowledgements, certificates and the audit log) is retained for the duration of your subscription, so you can demonstrate a multi-year training history to an auditor; it is append-only and exportable at any time. On termination, data is deleted or returned per the DPA. Per-person phishing-simulation data is minimized and used only for training and reporting, never for staff surveillance.

Access control & authentication

Role-based access (owner/admin/member). Leaked-password protection (HaveIBeenPwned) and MFA available. SSO/SAML ready for enterprise customers.

Compliance alignment

SecurityTask helps customers meet the training obligations of NIS2, ISO/IEC 27001, GDPR, DORA, and the Swiss nFADP, and is itself built around privacy-by-design and data minimization.

Our own certifications

Our platform is built to ISO/IEC 27001 information-security practices: EU hosting, encryption in transit and at rest, tenant isolation, append-only logs, and role-based access. Independent ISO/IEC 27001 certification — by an accredited body — is planned; until then, this page is our security statement.

Sub-processors

We use the following sub-processors to deliver the service. We update this list before adding new ones.

ProviderPurposeLocation
SupabaseManaged database, authentication & storageEU (Frankfurt)
VercelApplication hosting & deliveryEU / global (edge)
Resend (if email enabled)Transactional email delivery (invites, reminders, reports)EU / US

Responsible disclosure

Found a security issue? Email security@securitytask.com. We respond quickly and appreciate responsible disclosure.