A summary of our security posture. For personal-data processing, see the Privacy Policy and the Data Processing Agreement (DPA).
Data is hosted in the European Union (Frankfurt, eu-central-1 region) on a managed PostgreSQL database. GDPR-compliant EU hosting; no routine transfer of personal data outside the EU/EEA.
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Credentials are never stored in plaintext.
Every organization is isolated at the database layer using PostgreSQL Row-Level Security (RLS): a query can only ever reach its own organization’s data — enforced by the database itself, not just the application.
The admin audit log and training records (the compliance evidence) are append-only: the application can only insert and read them, never update or delete. Evidence cannot be altered or erased — not even by an administrator.
On the production plan, daily backups with point-in-time recovery (PITR). Evidence is also exportable to PDF/CSV and via the SIEM connector, so you can keep independent copies.
Training and compliance evidence (completions, policy acknowledgements, certificates and the audit log) is retained for the duration of your subscription, so you can demonstrate a multi-year training history to an auditor; it is append-only and exportable at any time. On termination, data is deleted or returned per the DPA. Per-person phishing-simulation data is minimized and used only for training and reporting, never for staff surveillance.
Role-based access (owner/admin/member). Leaked-password protection (HaveIBeenPwned) and MFA available. SSO/SAML ready for enterprise customers.
SecurityTask helps customers meet the training obligations of NIS2, ISO/IEC 27001, GDPR, DORA, and the Swiss nFADP, and is itself built around privacy-by-design and data minimization.
Our platform is built to ISO/IEC 27001 information-security practices: EU hosting, encryption in transit and at rest, tenant isolation, append-only logs, and role-based access. Independent ISO/IEC 27001 certification — by an accredited body — is planned; until then, this page is our security statement.
We use the following sub-processors to deliver the service. We update this list before adding new ones.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Managed database, authentication & storage | EU (Frankfurt) |
| Vercel | Application hosting & delivery | EU / global (edge) |
| Resend (if email enabled) | Transactional email delivery (invites, reminders, reports) | EU / US |
Found a security issue? Email security@securitytask.com. We respond quickly and appreciate responsible disclosure.