Data Policy

Last Updated: August 6, 2026Version 2.0

1. Zero-Retention Default

TaskVerified operates on a zero-retention default framework for work payloads. When text, code, or media files are submitted to our verification engine (via REST API, MCP Server, or the workspace upload), the files are processed in-memory. Once the 119 quality checks execute and the cryptographic JSON certificate is generated, the original payload content is instantly purged from our active processing memory. We do not copy, store, or train models on your proprietary work.

2. Cryptographic Audit Log (The Ledger)

To provide a tamper-proof verification history, TaskVerified logs transaction metadata (the "Ledger"). This log contains only non-sensitive identifying details and cryptographic hashes:

  • Timestamp: The exact UTC time when the verification occurred.
  • Verification Status: A binary pass/fail indicator.
  • SHA-256 Hash: A cryptographic signature of the file payload, proving its contents at the time of check without storing the actual file.
  • Metadata Indicators: Number of violations, execution duration, and matched categories (e.g. "Security Check", "SEO Check").

3. Data Sovereignty & Storage Tiers

For teams using our managed workspace, we offer flexible storage models:

  • Sovereign Storage (Recommended): Verified assets are automatically archived to your linked private cloud (Google Drive or Microsoft OneDrive) immediately after verification. TaskVerified stores no files.
  • Temporary Buffer Storage (Cloudflare R2): If Sovereign Storage is disabled, we store files in an encrypted Cloudflare R2 bucket. This is treated as a temporary buffer to facilitate validation reviews and pipeline orchestration, subject to standard cleanup schedules.

4. Encryption Pipelines

All data entering or exiting TaskVerified is secured using enterprise-grade protocols:

  • In-Transit: All connections require TLS 1.3 encryption (HTTPS/WSS) to prevent interception.
  • At-Rest: Database records (Neon PostgreSQL) and buffer storage (Cloudflare R2) are encrypted using AES-256 with managed key rotation.
  • Secrets Security: API keys and third-party storage credentials are encrypted at the field level using authenticated symmetric algorithms.

5. Retention and Scrubbing Schedule

We enforce automated data scrubbing schedules to protect user privacy:

  • Free Trial purges all buffered files and project metadata 7 days after the trial cancels or expires.
  • Subscription cancellations enter a 90-day hibernation period. If no subscription is active at the end of 90 days, all files are permanently deleted. Audit log indices are kept for 180 days solely for regulatory compliance.
  • Soft Delete requests enter a 30-day grace period where data can be recovered or exported, followed by permanent deletion.
Data Policy | TaskVerified — Forensic Data Governance | TaskVerified