Security

How your workspace data is protected

Alien Task holds your roadmap, your team's discussions, and in many cases your clients' project data. Here is the concrete detail on how that is handled — and what we have not built yet.

Controls

What is in place today

Encryption in transit and at rest

All traffic between your browser and Alien Task is encrypted with TLS 1.3. Stored data — tasks, comments, attachments, and account records — is encrypted at rest with AES-256.

Per-organization isolation

Every workspace is scoped to its own organization identifier, and that scope is enforced at the data-access layer on every query. A request authenticated for one workspace cannot read another's records.

Role-based access control

Permissions are assigned per workspace, so a contractor or client sees only the projects in their engagement. Changing someone's role takes effect immediately across every view.

Automated backups

Data is backed up automatically on a recurring schedule, with restore procedures exercised as part of routine operations rather than assumed to work.

Hardened infrastructure

Alien Task runs on managed cloud infrastructure with network-level restrictions, patched runtimes, and no direct public access to database layers.

Least-privilege internal access

Access to production systems is limited to the engineers who require it, and support staff cannot read workspace contents without an explicit, logged support request from a workspace administrator.

Detail

Data handling in practice

Where your data lives

Workspace data is stored in managed cloud database infrastructure with encryption at rest enabled at the storage layer. Attachments are held in object storage subject to the same encryption and the same per-organization access scoping as the records that reference them.

How AI features handle your content

The AI copilot processes the task, project, and discussion content you explicitly submit to it in order to generate breakdowns, briefings, and forecasts. Content is sent to model providers solely to produce that response. Alien Task does not sell workspace content, and does not use it to train third-party foundation models.

Access by our team

Production access is restricted to engineers who need it for operations and incident response. Support cannot browse the contents of your workspace as a matter of course — access for troubleshooting requires an explicit request from a workspace administrator and is recorded.

Your rights over your data

Workspace administrators can export their data and request deletion at any time by writing to [email protected]. Deletion requests remove workspace records from production systems, with residual copies ageing out of backups on the standard backup retention cycle. See the privacy policy for the full statement of rights under GDPR and CCPA.

Reporting a vulnerability

If you believe you have found a security issue, email [email protected] with the detail needed to reproduce it. We will acknowledge the report and keep you updated through remediation. Please give us a reasonable window to fix the issue before disclosing it publicly.

What we have not done yet

Alien Task is in open beta and we would rather state this plainly than let a certification badge be inferred. We do not currently hold a completed SOC 2 Type II or ISO 27001 certification. The controls described above are implemented and operating, but they have not been attested by a third-party auditor. If your procurement process requires formal attestation, write to us and we will tell you honestly where we are rather than where we intend to be.

Ready for liftoff?

Questions from your security team?

Send the questionnaire. We answer vendor assessments directly, and we will tell you when the answer is 'not yet'.

No credit card. Free during open beta.