Effective date: July 20, 2026·Last updated: July 20, 2026
BLUELINKS GROUP LTD (company no. 16277222), registered office: 167-169, 5th Floor, Great Portland Street, London, England, W1W 5PF, trading as Bluelinks Agency.
This page describes, plainly and accurately, how TaskGlaze protects your data — hosting, encryption, access control, backups, and how to report a vulnerability. Every claim here is checked against our real, current implementation, not written for effect.
On this page
This Security Policy describes the real technical and organizational controls we use to protect TaskGlaze and the data it holds. We'd rather this page state exactly what we do than read impressively and be wrong — every control listed below reflects our actual, current implementation, not an aspirational target. We may update these controls over time; any update will not materially reduce the protections described here without notice.
TaskGlaze's application and database servers are hosted with Hetzner, in a data center in Nuremberg, Germany (EU). Our host firewall (UFW) is default-deny — only SSH (22), HTTP (80), and HTTPS (443) are reachable from the public internet; every other service, including PostgreSQL (5432) and Redis, is restricted to internal, Docker-only network ranges and cannot be reached from outside our infrastructure at all.
Administrative access to customer data is restricted to designated staff accounts, gated by an admin-only flag in our system plus mandatory two-factor authentication on that specific account — an admin account without 2FA enabled is denied access outright, not just warned. Every admin action against customer data is written to an internal audit log.
Account-level protections available to every TaskGlaze user: optional two-factor authentication (TOTP, free on every Plan), account lockout after repeated failed login attempts, and rate limiting on every authentication-related endpoint (login, password reset, verification) at both the per-account and per-IP level.
The Outreach CRM's optional mailbox connection is treated as a particularly sensitive integration: credentials are encrypted at rest (AES-256-GCM), reply-checking always opens the mailbox in IMAP read-only (EXAMINE) mode so the mail server itself refuses any state change for the duration of the connection, and disconnecting a mailbox deletes the stored credential immediately rather than leaving it in a deactivated row. Full detail is in the Privacy Policy's "Connected email accounts" section.
We run automated weekly and monthly full-system backups (including the database), encrypted, with weekly backups retained on a rolling ~5-week window and monthly backups retained for 12 months. Backups are stored off-site (encrypted, not readable without our separately-held encryption key) for disaster-recovery purposes, and backup completion is monitored with automatic alerting on failure.
We only engage third-party providers (Subprocessors) necessary to operate specific features, and only with a written agreement in place covering confidentiality and data-protection obligations. Our current Subprocessors, and what each one can access, are listed in full in our Privacy Policy.
If we become aware of a security incident affecting personal data, we investigate, take reasonable steps to contain and remediate it, and notify affected users and any relevant authority as required by applicable law — see the Data Processing Agreement's "Personal Data Breaches" section for the specific notification commitment we make to business customers.
We do not currently run a paid bug bounty program. If you believe you've found a genuine security vulnerability in TaskGlaze, please report it to support@taskglaze.comwith enough detail to reproduce it. We ask that you not access, modify, or exfiltrate data beyond what's strictly necessary to demonstrate the issue, and that you give us a reasonable opportunity to fix it before any public disclosure. We will acknowledge a good-faith report and keep you updated on remediation.
Security is shared: enable two-factor authentication on your Account, use a strong, unique password, use an app-specific password where your mailbox provider supports one instead of your primary account password when connecting a mailbox, and keep the device you access TaskGlaze from reasonably secure. See the Terms of Service's "Account registration & security" section for the full allocation of responsibility.
We may update this Security Policy as our infrastructure and practices evolve. Material changes will be reflected here with an updated "Last updated" date; we will not materially reduce the protections described here without prior notice on this page.
BLUELINKS GROUP LTD, trading as Bluelinks Agency (operating TaskGlaze), can be reached for any security question at support@taskglaze.com.
Questions about this document?
Contact us at support@taskglaze.com and we'll get back to you within a few business days.
BLUELINKS GROUP LTD (company no. 16277222), 167-169, 5th Floor, Great Portland Street, London, England, W1W 5PF.