Security
Written for IT, security and procurement teams evaluating EasyTask.
EasyTask holds a business's day-to-day work: tasks, internal chat, customer leads and attachments. This page sets out how we protect it. If your onboarding process needs something not answered here, email support@marothiatechs.com and we will answer directly rather than send you a brochure.
Data residency
All EasyTask application servers, databases and file storage run in the Amazon Web Services Asia Pacific (Mumbai) region, ap-south-1. Your work content stays in India. The exception is push notification delivery and, where you use it, Google Sign-In, which are handled by Google's global infrastructure.
Encryption
- In transit. Every connection between the apps and our servers uses TLS, terminated at a managed load balancer with certificates that renew automatically. Plain HTTP requests are redirected to HTTPS. The real-time chat socket runs over the same TLS endpoint (
wss://). - At rest. Storage volumes and backups are encrypted at the infrastructure layer.
Access control
- In the product. Access is scoped by workspace and by role. A member sees only the workspaces they belong to, and every API request is authorised against that membership on the server — not in the client.
- Sessions. Sign-in is by one-time password to a verified mobile number, or Google Sign-In. Sessions use short-lived signed access tokens that expire and are refreshed, so a leaked token has a small window. The real-time socket independently verifies the signed token on every connection and reconnection.
- To production. Restricted to a small number of named staff, each using individually issued credentials rather than a shared password, across a private network. Our databases are not exposed to the public internet.
- Secrets. Credentials and signing keys are held outside the application repository, are reachable only by the staff who operate the service, and are never shared over chat or email.
How we build and run it
- Production is deployed from version control by a scripted, repeatable process, so what is running is always a known commit and can be rolled back to the previous one.
- Each deploy runs an automated health check, and the load balancer removes an unhealthy server from rotation.
- Server and application errors are logged and reviewed.
- Operating system and dependency updates are applied on a regular cycle, and out of cycle for anything security-critical.
- Databases are backed up on a rolling schedule, and restores are practised rather than assumed.
Sub-processors
| Provider | What they do for us | Where |
|---|---|---|
| Amazon Web Services | Application hosting, database and file storage | Asia Pacific (Mumbai), ap-south-1 — India |
| Google Firebase | Push notifications, authentication, call signalling, aggregate analytics | Google global infrastructure |
That is the complete list. We do not use advertising networks, data brokers or third-party analytics beyond the aggregate usage counts named above, and we do not sell or share customer data. We will tell existing customers before adding a sub-processor that handles personal data.
Privacy and data protection
We act as the data fiduciary for account data and as a processor for the content a customer's workspace holds. Our privacy policy sets out the categories, the legal basis and the rights available, and our deletion page sets out the deletion timeline — 30 days to action, 90 days for backups to expire. We can sign a data processing agreement; ask us.
Incident response
If we become aware of a security incident affecting your data we will investigate immediately, contain it, and notify affected customers within 72 hours of confirming it, with what happened, what data was involved and what we are doing about it. Where Indian law requires us to report to CERT-In or another authority, we do so within the statutory timeline.
Reporting a vulnerability
If you have found a security issue in EasyTask, please tell us at support@marothiatechs.com with enough detail to reproduce it. We will acknowledge within two working days and keep you updated until it is fixed. Please give us reasonable time to fix an issue before disclosing it, and do not access or modify data that is not yours while testing. We will not pursue action against researchers who follow that.
Independent assurance and your questionnaire
We will tell you plainly which controls we operate and which we do not, our current certification and independent-testing status, and any evidence we can provide — in writing, as part of your review, and under an NDA first if you prefer. Send us your questionnaire and we will complete it rather than point you at this page.
We would rather answer your specific questions honestly than publish a general claim.
Contact us
Questions about this document, or a request about your data? Email support@marothiatechs.com or call +91 75728 57390. Post: 509, Saket Textile Market, near Aai Mata Circle, Parvat Patiya, Surat, Gujarat 395010, India.