Security

Last updated: August 13, 2026

This page is the public vulnerability-reporting policy for TaskGeniusAI. Researchers and customers can also read the machine-readable file at /.well-known/security.txt.

How to report a vulnerability

Email security@taskgenius.ai (or your account team contact) with:

  • A description and the likely impact
  • Steps to reproduce
  • Affected routes or a workspace slug if the issue is tenant-specific

We aim to acknowledge within 2 business days and share a remediation timeline for confirmed issues.

Supported deployments

Production web (app.taskgeniusai.com) and the workers host that shares the same database and Redis are in scope. Local development is not a security boundary and must not use production secrets.

What not to include

Do not send customer data, live credentials, or exploit payloads that change another tenant's account. If you need a test workspace, say so in the report and we will arrange one.

Product and privacy questions

Billing, onboarding, and day-to-day product help go to /support. Privacy requests are covered on the Privacy Policy.