Skip to content
Taskiim

Security is not a paid tier

Workspace isolation, upload scanning, signed file links and the audit log are on every plan including Free. Putting any of them behind a price would make the cheap tier the unsafe one — which is bad selling, and true of whatever ships it.

Every upload passes three gates

Each one answers a different question, and they run in this order — because these files are served back to other people in the workspace.

  1. 1

    What is it

    The declared content type is ignored. A file is identified from its magic bytes, and an Office document is recognised by parsing its ZIP directory — never by decompressing it.

  2. 2

    Can it execute

    A package carrying a VBA project or an Excel 4.0 macro sheet is refused. A macro-enabled file renamed to .xlsx is structurally valid, so this is the gate that catches it.

  3. 3

    Is it hostile

    The bytes are streamed to a malware scanner before they reach storage, so an infected file never becomes an object. If the scanner is unreachable the upload is refused — an outage must not quietly become a bypass.

SVG is excluded deliberately. It is an image that can carry script, and these files are shown to colleagues.

How the rest of it works

Every row carries its workspace

Tenant scoping is applied by the database layer itself rather than remembered at each query, and one workspace reading another’s rows is asserted against a real database in the test suite.

Permissions are read per request

Access tokens carry an identity, never a permission list. Revoking a role takes effect on the next request instead of whenever a token happens to expire.

Refresh tokens rotate, and reuse is detected

Presenting a token that has already been rotated revokes the whole family. The forced re-login is the intended outcome.

Files are private by default

The bucket is not public. Reads go through short-lived signed links minted per request, so revoking access is a database change rather than a file move.

The audit log is append-only

No updates, no deletes. A smaller plan sees a shorter window of history — the rows themselves are never removed.

Sign-in without a password

Google sign-in and passkeys. Users are provisioned by invitation; signing in with an unknown address is refused rather than silently creating an account.

Two things we deliberately do not have

There is no impersonation. Support cannot log in as you. If seeing a workspace ever becomes genuinely necessary, that belongs behind a time-boxed grant the customer starts and sees in their own audit log — not behind an operator's convenience.

And there is no cross-workspace search. Operating the platform needs to know how much there is and whether it is healthy; none of that requires reading anyone's tasks. Every operator query returns counts and structural columns, and a test asserts against a real database that no text a customer typed appears in an operator's response.

Open the audit log yourself

The demo includes the audit trail. Move a card, approve a week, then read back exactly what was recorded about it.

Try the live demo