What runs where, and what we can see
TaskMate asks you to install software that drives your browser and touches your files. That's a real ask, so here's a straight account of how it works — the kind of page we'd want to read before installing something ourselves.
Execution is local
Tasks run on your machine, in your own browser session, against your own files. There is no cloud worker logging into your portals on your behalf.
Releases are code-signed
Every installer is signed, and we publish the SHA-256 checksum next to the download so you can verify what you have is what we built.
We keep the minimum
Account details, plan and credit usage, and run metadata for your history. Not your documents, not your portal contents.
One distribution channel
TaskMate is only ever downloaded from taskmate.deccanlogic.com. If you find an installer anywhere else, it isn't ours.
What stays on your machine, and what reaches us
| Stays local | Reaches our servers | |
|---|---|---|
| Portal and app credentials | Yes | — |
| Browser session cookies | Yes | — |
| Files a task reads or writes | Yes | — |
| The page contents a task works with | Yes | — |
| Your account and plan | — | Yes |
| Credit usage per run | — | Yes |
| Run metadata (task name, timing, pass/fail) | — | Yes |
| Content of an AI-assisted step | — | sent to the model provider, for that step only |
Why a desktop application
The honest answer is that the alternative doesn't work for what TaskMate does. To drive the portals you're already logged into and touch the files on your disk, the software has to be where those things are. A cloud version would mean handing us your credentials and uploading your documents — which is precisely the thing most of our users tell us they don't want to do.
Verifying a download
Each release page publishes the SHA-256 of the signed installer. On Windows, certutil -hashfile TaskMate-Setup.exe SHA256; on macOS, shasum -a 256 TaskMate.dmg. If the value doesn't match what's published, don't run it, and tell us.
If your IT team wants to review it
Write to us. We'd rather spend an hour with a security reviewer than have you install something you're not sure about. We can walk through what the app does at runtime, what network calls it makes, and what's stored where.
Reporting something
If you find a vulnerability, email us directly rather than filing it publicly, and we'll work with you on a fix and a disclosure timeline. We're a small team — you'll be talking to someone who can actually change the code.
Stop being the integration between your own tools.
Start on the free plan — 150 credits every month, no credit card, no sales call.