Security

How Your Workspace Is Protected

My First Task is a young, pre-launch product — this page describes what's actually built today, not a compliance checklist. We'll update it honestly as more is added.

Product Preview
Screenshot of workspace roles / permissions settings
/images/security/workspace-roles-screenshot.jpg
Workspace data isolation
Every project, task, and issue is scoped to a single workspace at the database level — one workspace can't read or write another's data.
Role-based access
Owner, Admin, Member, and Viewer roles control what each person in a workspace can see and change, down to the project level.
Full activity log
Every meaningful action on a project, task, or issue is recorded with who did it and when — visible to admins for accountability.
Google sign-in
Authentication runs through Google sign-in rather than a separate password store to manage.
Brute-force protection
Login attempts are rate-limited, with per-account lockout after repeated failures — guarding against both targeted and distributed attacks.
Restricted cross-origin access
The API only accepts requests from an explicit allowlist of origins, not any website that asks.

What We Don't Claim

We don't currently offer SSO/SAML, and we haven't pursued formal certifications like SOC 2 — both are reasonable things to ask about as your team grows, and we'd rather say so plainly than let a badge on this page imply otherwise. If either is a requirement for your team, reach out and let us know.

Questions About Security?

We're happy to talk through anything on this page in more detail.

Start Free