Product
Operations Finance HR
Integrations Pricing Blog
Start free
Security

Data residency in Japan. Controls designed for enterprise review.

All workflow data stored in Japan-region data centers. TLS 1.3 in transit, AES-256 at rest. Role-based access control with four roles. Full execution log on every workflow run — retained 90 days on Team plans, 365 days with export on Business.

Security documentation

Data storage — Japan region, isolated per account

All customer workflow data, run logs, and configuration is stored in Japan-region data centers. We do not transfer workflow execution data or customer content outside Japan under normal operating conditions.

Each customer account operates in an isolated data partition. Workflow run data from one account is never accessible to another account, either through the TASKBASE interface or via API.

  • Data center region: Japan (Tokyo)
  • Account isolation: logical separation with separate encryption keys per account
  • Backup retention: 30-day rolling backup in the same Japan region

Encryption in transit and at rest

All data transmitted between your browser and AVIATE servers is encrypted using TLS 1.2 or higher. We do not support older TLS versions or weak cipher suites.

Data at rest — including workflow definitions, run logs, and any user-submitted content processed by AI steps — is encrypted using AES-256 at the storage layer.

  • In transit: TLS 1.2+ (TLS 1.3 preferred)
  • At rest: AES-256 encryption at the storage layer
  • Integration credentials (OAuth tokens, API keys): encrypted at rest, never visible after initial setup

Access control — role-based

TASKBASE implements role-based access control (RBAC) at the workflow and organization level. Administrators can define what each team member can view, build, run, and approve.

  • Admin: full organization and workflow management
  • Builder: create and edit workflows; cannot manage billing or members
  • Operator: run workflows and action approval requests; cannot edit workflow definitions
  • Viewer: read-only access to run history and dashboards

SSO (SAML 2.0) is available on the Business plan, allowing organizations to enforce identity provider policies for TASKBASE access.

Run log retention

Every workflow execution is logged with a complete record of: trigger data, each step's input and output, approval decisions (who acted, when, and their decision), branching paths taken, and any errors.

Run logs are retained for 90 days on Starter and Team plans, and 365 days on the Business plan. Business plan customers can export full audit logs in JSON format for compliance and internal audit purposes.

  • Starter / Team: 90-day log retention
  • Business: 365-day log retention with export
  • Log data includes: actor identity, timestamp, step inputs/outputs, approval decisions

Responsible disclosure

If you discover a potential vulnerability in AVIATE or TASKBASE, please disclose it to us privately before publishing. We are a small team and take security reports seriously.

Email [email protected] with the subject "Security Disclosure". We will acknowledge your report within 2 business days (JST) and respond with a timeline for addressing confirmed vulnerabilities.

We credit researchers who report verified vulnerabilities, if they request credit. We do not have a formal bug bounty programme at this stage.

What AVIATE is not: AVIATE is not a certified SOC 2 Type II or ISO 27001 organisation. We have built security controls consistent with those frameworks and we work toward formal certification as the product grows. If your procurement process requires a certified attestation today, please contact us to discuss whether our current controls documentation meets your evaluation criteria.

Questions for your procurement review?

Our team can provide detailed security documentation, data processing agreements, and answers to vendor security questionnaires. We respond within 1 business day (JST).