Security

What runs where, and what we can see

TaskMate asks you to install software that drives your browser and touches your files. That's a real ask, so here's a straight account of how it works — the kind of page we'd want to read before installing something ourselves.

Execution is local

Tasks run on your machine, in your own browser session, against your own files. There is no cloud worker logging into your portals on your behalf.

Releases are code-signed

Every installer is signed, and we publish the SHA-256 checksum next to the download so you can verify what you have is what we built.

We keep the minimum

Account details, plan and credit usage, and run metadata for your history. Not your documents, not your portal contents.

One distribution channel

TaskMate is only ever downloaded from taskmate.deccanlogic.com. If you find an installer anywhere else, it isn't ours.

What stays on your machine, and what reaches us

 Stays localReaches our servers
Portal and app credentialsYes
Browser session cookiesYes
Files a task reads or writesYes
The page contents a task works withYes
Your account and planYes
Credit usage per runYes
Run metadata (task name, timing, pass/fail)Yes
Content of an AI-assisted stepsent to the model provider, for that step only

Why a desktop application

The honest answer is that the alternative doesn't work for what TaskMate does. To drive the portals you're already logged into and touch the files on your disk, the software has to be where those things are. A cloud version would mean handing us your credentials and uploading your documents — which is precisely the thing most of our users tell us they don't want to do.

Verifying a download

Each release page publishes the SHA-256 of the signed installer. On Windows, certutil -hashfile TaskMate-Setup.exe SHA256; on macOS, shasum -a 256 TaskMate.dmg. If the value doesn't match what's published, don't run it, and tell us.

If your IT team wants to review it

Write to us. We'd rather spend an hour with a security reviewer than have you install something you're not sure about. We can walk through what the app does at runtime, what network calls it makes, and what's stored where.

Reporting something

If you find a vulnerability, email us directly rather than filing it publicly, and we'll work with you on a fix and a disclosure timeline. We're a small team — you'll be talking to someone who can actually change the code.

This page describes how the product works today, at MVP stage. It isn't a compliance certification, and we won't pretend otherwise — if you need formal attestations, talk to us about what your process requires.

Stop being the integration between your own tools.

Start on the free plan — 150 credits every month, no credit card, no sales call.

Start Free Trial Talk to us