Encryption

Connections use transport encryption, and sensitive integration credentials receive additional application-level protection where implemented.

Access Controls

Organisation membership and role-based permissions limit application access. Customers control invitations and roles and must remove access when it is no longer authorised.

Audit Evidence

Key workflows retain operational history such as original and adjusted times, approval reasons, legal acceptances, requirement reviews, and payroll export status. Coverage varies by feature.

Monitoring

Error monitoring and application logs help us identify and investigate faults. Availability is not guaranteed unless agreed in a separate service-level commitment.

Privacy and Workforce Compliance

Australian Privacy

Our privacy program and contractual controls are designed around Australian privacy requirements. The Privacy Act and Australian Privacy Principles apply where their legal thresholds and scope are met.

Data Breach Response

We investigate suspected incidents, notify materially affected customers, and support assessment under the Notifiable Data Breaches scheme. Required regulator or individual notifications depend on the facts and which entity has the legal obligation.

Customer Decisions

TaskForceOne supports record-keeping, award, payroll, and surveillance workflows but does not certify a customer's Fair Work or employment-law compliance. Customers must configure, verify, export, and retain their required records.

Security Practices

  • Application security: framework protections, access checks, request validation, and rate controls are used according to the relevant component and risk.
  • Credential handling: passwords are hashed; integration secrets and selected sensitive credentials are encrypted or tokenised rather than stored as ordinary plaintext application fields.
  • Provider management: providers are selected for defined operational purposes and listed in our Service Provider and Subprocessor Register.
  • Reported incidents: security reports are assessed according to their apparent severity, affected data, and applicable legal requirements.
  • Data lifecycle: deletion and de-identification follow the behavior described in our Privacy Policy and Account Deletion page.

Customer Security Responsibilities

  • Use individual accounts, strong authentication, and secure managed devices.
  • Assign the least role needed and promptly archive departing personnel.
  • Review location, payroll, document, and integration settings before enabling them.
  • Protect exported reports and payroll files after they leave TaskForceOne.
  • Report suspicious access, inaccurate records, or lost devices promptly.

Report a security concern

Use our responsible-disclosure process for a suspected vulnerability, or contact support immediately for an active account incident.