Legal

Security & Data Practices

Last updated August 26, 2026. An overview of how we build and operate GovTasks. This page describes our practices; it is not a certification or audit report.

Tenant separation

Every business profile, saved opportunity, pursuit, task, and document belongs to a single organization. Access is enforced in the database with row-level policies keyed to your organization membership, not only in the application interface, so a request for another organization's records returns nothing.

Access control

  • Authentication is handled by our managed identity provider; passwords are never stored by GovTasks in readable form.
  • Roles are stored separately from user profiles and checked server-side, so permissions cannot be changed from the browser.
  • Administrative tooling is restricted to GovTasks staff accounts and is separate from customer workspaces.

Data in transit and at rest

Traffic to GovTasks is served over HTTPS, and customer data is stored in our managed hosting provider's encrypted infrastructure. Payment card details are handled entirely by our payment processor and never reach our servers.

AI processing

AI features send solicitation text and relevant profile details to third-party providers to generate summaries, requirement lists, and explanations. Those surfaces are labeled in the product. Fit scoring, deadline math, and permission checks are deterministic and never delegated to a model.

What we ask of you

  • Use a unique, strong password and keep team access limited to people who need it.
  • Do not upload classified, controlled-unclassified, or export-restricted material to GovTasks.
  • Remove team members promptly when they leave your organization.

Reporting a vulnerability

If you believe you have found a security issue, email security@govtasks.com with steps to reproduce. Please give us a reasonable window to investigate before public disclosure, and avoid accessing data that is not yours while testing.