Skip to content
Security posture

Security at Taskcenter.

TaskCenter combines organization-scoped access, reviewable agent execution, and server-owned records so consequential work stays attributable and inspectable.

Updated August 17, 2026

This is a product security overview, not a certification claim. Controls described as conditional depend on the configured deployment and provider.

Scoped access

Protected server operations require an authenticated actor, organization context, and the relevant permission.

Reviewable execution

High-impact agent actions can be staged as proposals instead of being silently applied.

Durable evidence

Audited writes, run records, and artifacts help explain what acted, when, and within which workspace.

01

Identity and sessions

Authentication is handled server-side and protected routes do not rely on presentation-layer checks.

  • Password and supported email link/code sessions use secure, HttpOnly session cookies; access is resolved against the authenticated account and organization.
  • Google sign-in uses OAuth 2.0 / OpenID Connect authorization code flow with PKCE S256, state, nonce, issuer and audience checks, verified email checks, and Google JWKS signature verification.
  • Login and account flows can require Cloudflare Turnstile. Administrative and runtime capabilities remain outside the public navigation and require explicit authorization.

02

Authorization and data boundaries

Server-owned policy and guarded adapters enforce the workspace boundary.

  • Role-based permissions are checked for protected operations, including connector and billing actions; absent permission is denied rather than inferred from the UI.
  • D1 access for governed features is routed through guarded data adapters with an actor, organization, feature block, and audit metadata.
  • Secrets and provider credentials are not marketing-page state. They are held in configured runtime bindings or delegated to an approved connector provider when that flow is used.

03

OAuth and connected services

Connection flows are scoped, stateful, and explicit about readiness.

  • Native connector authorization uses short-lived organization-scoped state and PKCE where supported. A callback must match the stored state before a connection record can advance.
  • A generic connector callback does not currently claim token custody: where automated exchange is not implemented, the account is recorded as needing reauthorization and operator action.
  • Composio-backed connections use authenticated, permission-checked authorization sessions. Provider scopes and downstream availability still depend on the selected provider and workspace configuration.

04

Agent and automation safety

AI convenience is subordinate to capability readiness and human review.

  • Consequential mutations can be presented as proposals with visible scope and approval state before apply.
  • Completion claims should be supported by backend state, verification output, or attached evidence rather than generated narration alone.
  • Browser, sandbox, queue, model, and connector capabilities are shown as unavailable or gated when their supporting runtime is not ready.

05

Infrastructure and reporting

The deployed service uses configured Cloudflare primitives and third-party providers.

  • Cloudflare may provide application hosting, Workers runtime, D1 storage, Durable Objects, queues, object storage, security controls, and related infrastructure depending on deployment configuration.
  • Stripe may process billing; Google may provide identity; Composio and individual connector providers may process authorization or connected-service requests; configured AI providers process model inputs needed for a request.
  • Report a suspected vulnerability or security incident to security@taskcenter.co. Do not include secrets or personal data beyond what is needed to investigate.

Questions about this document?

Contact privacy@taskcenter.co for questions about privacy or terms. To report a security issue, contact security@taskcenter.co.