Your project data.
Handled securely.

Owners, contractors and operators keep plans, production data, completion records and O&M documentation in TaskCtrl. This page shows how we protect that data and how our controls have been assessed by an independent third party.

Independently assessed.

TaskCtrl has been assessed through the Assured SaaS Security Assessment. It covers 128 controls across governance, access control, encryption, operations, secure development, privacy and business continuity. Our answers have been reviewed by Assured's security team.

82.7
Assured score out of 100
76.7
Average across assessed services
128 / 128
Controls answered
September 2026
Latest review

How we protect your data.

Hosting and data residency

  • The service runs on Google Cloud.
  • Customers choose whether their data is stored in the EU or the US. Other regions can be agreed.
  • Project data, files and backups stay in the chosen region.
  • Sign-in data is processed by our authentication provider in the US, under an approved GDPR transfer mechanism.
  • Each customer's data is kept separate from other customers.

Encryption

  • All communication is encrypted.
  • Data and backups are encrypted where they are stored.
  • Encryption keys are managed and rotated automatically.

Sign-in and user access

  • Two-factor and passwordless sign-in.
  • Single sign-on with your own corporate directory.
  • Individual users with roles and permissions. No shared accounts.
  • Customers control who has access to their own projects.

Our access to customer data

  • Staff have no access to customer data without an approved need.
  • Everyone with operational access uses two-factor sign-in.
  • Access is reviewed every quarter.
  • All elevated access is logged and followed up.

Operations and availability

  • Target of 99.9% monthly uptime, agreed in our SLA.
  • For major outages, the target is to be back up within one hour, with no more than one hour of data loss.
  • Restoring from backup is tested every month.
  • Critical incidents: response within one hour, 07:00 to 23:00 CET every day.

Secure development

  • Separate environments for development, test and production.
  • All code is reviewed before release.
  • Independent penetration testing twice a year and after major changes.
  • Ongoing security updates.

Privacy and ownership

  • Personal data is processed in line with the GDPR.
  • Customers own their data. It is used only to deliver the service.
  • Customers are notified without undue delay of any data breach.
  • On termination, customers get their data back and everything is deleted within 60 days.

AI and Silicon Agents

  • AI is off by default. Customers enable it per organization or project.
  • AI processing takes place in the same region as the customer's data.
  • Customer data is not used to train AI models.
  • Agents propose, users approve. Nothing changes without approval.
  • Agents never have more access than the user, and only within their own project.
  • AI-generated content is clearly marked.

Governance and readiness

  • Security policy approved by management.
  • Defined roles and procedures for security incidents.
  • Regular risk assessments.
  • Annual security training and confidentiality agreements for everyone.
  • No security incidents requiring notification in the past two years.

Documentation on request.

If you are evaluating TaskCtrl in a procurement or tender, we will send the material directly.

  • Data processing agreement
  • Service level agreement (SLA)
  • List of sub-processors
Request documentation

Last updated October 2026. Security controls assessed in the Assured SaaS Security Assessment, reviewed 1 September 2026. The AI section was added after the assessment.