Security & Trust
This page is maintained by the Stratask team to answer common security and privacy questions about Stratask. It describes the controls we have in place today and is not an independent certification or audit report.
Authentication & access
Stratask uses email/password and Google sign-in. Sessions are issued by our managed auth provider and stored as short-lived tokens in the browser. Access to your company's data is gated by membership: only active members of a company can read or modify that company's objectives, projects, and tasks.
Admin-only actions (such as transferring company ownership or approving new members) require an active admin role on the company.
Data protection
All traffic to Stratask is served over HTTPS. Application data is stored in a managed Postgres database with encryption at rest provided by the hosting platform. Row-Level Security policies enforce that each query only returns rows the signed-in user is authorized to see.
Privileged service credentials are kept server-side and are never exposed to the browser.
Hosting & subprocessors
Stratask runs on the Lovable Cloud platform, which provides our application hosting, managed database, authentication, and transactional email infrastructure. Outbound email is delivered through our email provider with bounce, complaint, and unsubscribe handling.
Email & unsubscribe
We send transactional emails (task notifications, comments, reminders, member approvals). Every email includes an unsubscribe link. Suppressed addresses are honored across the system and cannot be re-subscribed by other users.
Data retention & deletion
Your project, task, and comment data is retained while your company is active. If you need data exported or deleted, contact us at the address below and we will respond within a reasonable timeframe.
Reporting a security issue
If you believe you've found a security vulnerability or have a concern about how Stratask handles your data, please email us directly:
Please include a description of the issue, steps to reproduce, and any relevant URLs or screenshots. We ask that you give us a reasonable opportunity to investigate and remediate before public disclosure.
Shared responsibility
Stratask provides the platform controls described above. As an account holder, you're responsible for using a strong, unique password, keeping your sign-in credentials confidential, managing who you invite to your company, and promptly removing members who should no longer have access.
Last updated: June 2026. This page is editable project content and will be revised as our practices evolve.