Skip to content

Security

Your business data, kept to itself.

Your orders, prices, customers and takings are the business. Here is how we keep them safe, in plain words.

What we do

Six things that protect every business.

The same protections apply to every account, whatever the plan.

  • Each business kept apart

    Every request is checked on our servers against the business it belongs to, so one business can never read another’s records. A sign-in only works on the address it was made on.

  • Strong sign-in

    Passwords are stored only as one-way hashes. Two-step sign-in with an authenticator app is available, and a business can require it for its admins. Repeated failed sign-ins are blocked.

  • Roles and permissions

    Staff see and do only what their role allows: the till, the warehouse or the money. The owner decides who gets what.

  • Encrypted and hosted in the UK

    Every connection uses HTTPS. The platform and its database run in DigitalOcean’s UK region, the database is backed up daily, and keys for connected accounts are encrypted with AES-256-GCM.

  • AI with guard rails

    The AI assistant reads only the records of the business it is working for. Instructions hidden inside data are fenced off and tested for, and it asks before it changes anything.

  • Checked on every release

    Automatic tests and checks run on every change. Errors are monitored, and each release is health-checked as it goes live and rolled back automatically if it fails.

Data protection

Under UK law, and registered.

Tech Me Today Ltd handles personal data under the UK GDPR and the Data Protection Act 2018, and is registered with the Information Commissioner’s Office (registration no. ZB944663).

For the records a business keeps about its own customers and staff, that business decides how they are used and we act only on its instructions. The data is never sold and never used for advertising.

The privacy policy lists every provider we use, what each one is for, and how long we keep data.

Reporting a security issue

Found something? Tell us first.

Email support@easytaskr.com with “Security” in the subject, and include the steps to see the problem. A person reads every report.

  • Only use your own account or test data; do not open, change or delete anyone else’s.
  • Do not run tests that slow the service down or flood it with traffic.
  • Give us a reasonable time to fix the problem before telling anyone else.

In more detail

How your data is protected, in more detail

Sign-ins are limited and locked after repeated failures, two-step codes come with one-time backup codes, sessions end on every device when you sign out or change your password, every important change is written to an activity log admins can read, the database is backed up daily, and private files open only through short-lived links.

Step by step: securing your business account

The protections described above apply to every account automatically. These steps are the part only you can do, and they take about fifteen minutes the first time.

  1. Turn on two-step sign-in for yourself. Open Settings, then Security, and choose Set up two-step sign-in. Scan the code with an authenticator app on your phone and type the six-digit code it shows.
  2. Keep your backup codes somewhere safe. You are given 10 one-time codes. Print them or store them in a password manager, not in an email to yourself. Each code works once if your phone is lost.
  3. Require two-step sign-in for every admin. On the same page, under For your whole business, switch on Require two-step sign-in for admins. Admins who have not set it up can still sign in, but cannot do anything else until they have.
  4. Give each person their own login. Shared logins make the activity log useless, because every change looks like the same person. Add staff under Users and roles.
  5. Give each person the smallest role that does the job. A cashier needs the till, not the bank details. A warehouse role needs stock, not customer balances. See the table below.
  6. Check what each role can open. Admins and owners can adjust, in the permissions settings, which parts of EasyTaskr a role or an individual can open.
  7. Remove leavers on their last day. In Users and roles, deactivate or remove their user straight away, so their login stops working.
  8. Look at the activity log once a week. Open Settings, then Activity. Filter by Team and sign-ins to see who signed in and any changes to users and roles.
  9. Report anything odd. If you see a sign-in or a change you do not recognise, change your password (which signs you out everywhere) and email us, as described above.

Which role should each person have?

Roles decide what someone sees the moment they sign in. The main ones are:

RoleTypical personWhat it is for
Owner or tenant adminThe owner, a directorEverything, including users, roles and business settings
ManagerShop or branch managerDay-to-day running, reports and the activity log
Sales manager / sales repSales teamCustomers, orders and price lists
Warehouse manager / warehouse staffStores and dispatchStock, goods in, counts and picking
Finance or accountantBookkeeperInvoices, payments, who owes what and reports
CashierCounter staffThe till
Kitchen, waiter, driverRestaurant and delivery staffThe kitchen screen, tables or the delivery app

Restaurants have their own roles because a kitchen screen and a waiter's tablet need very different screens. A business can also create custom roles when the standard ones do not fit.

How are sign-ins protected?

Sign-in is where most break-ins start, so it has several layers.

  • Passwords must be at least 10 characters, and are stored only as bcrypt hashes. Nobody, including us, can read them back.
  • Wrong attempts are limited. Five wrong passwords or two-step codes lock that account for 15 minutes. Separately, an internet address that keeps failing to sign in is blocked from signing in, for 24 hours by default, which stops one machine trying many accounts.
  • Requests are rate-limited. Each address can only make so many sign-in requests a minute, and the service as a whole limits how fast any one address can call it. A client that goes over is told to wait.
  • Two-step codes follow the standard used by common authenticator apps. Backup codes are stored only as hashes and work once each.

How long does a session last?

Your sign-in is held in a secure cookie that the browser keeps away from page scripts, sent only over HTTPS, and tied to the address you signed in on. A session lasts up to 24 hours before it is quietly renewed in the background. If you do not use EasyTaskr for 7 days, you must sign in again.

Each renewal replaces the old one. If an old renewal is ever used again, which is a sign that someone has copied it, every session for that user is ended at once.

All of your sessions end, on every device, when you:

  • sign out,
  • change or reset your password,
  • have your two-step sign-in reset by an admin, or
  • become subject to a new rule requiring two-step sign-in for admins.

What does the activity log record?

The activity log answers "who changed this?" without guesswork. Important actions are written to it as they happen: sign-ins and failed sign-ins, role changes, exports, and changes to records such as products, prices, customers, orders and payments. Each entry records who did it, what changed (before and after), when, and from which internet address and device.

In Settings, then Activity, admins, owners and managers can filter by area (Sales and orders, Products and stock, Customers, Payments and expenses, Team and sign-ins, Account and settings), by person and by time range.

How are backups and files handled?

The database is copied in full every night to separate storage. The backup routine keeps the last 30 daily copies, then one copy a week for 12 weeks, one a month for 12 months and one a year for 5 years, so an older state of the data can be recovered if a problem is only noticed later.

Files you upload, such as job cards, warranty claims and condition photos, are private by default. They open only through a signed link that expires, after one hour by default, so a link copied into the wrong chat stops working. Pictures meant for the public, such as product photos on your online shop or blog images, are stored as public files on purpose.

What else runs in the background?

  • HTTPS everywhere. Plain web requests are redirected to HTTPS, and browsers are told to use HTTPS only for the next year.
  • Browser protections. Pages are sent with headers that stop them being framed by other sites and stop browsers guessing file types. Signing pages run under a strict content security policy.
  • Error monitoring without personal data. When something breaks, the error is reported to our monitoring service with personal data switched off, so we can fix it without collecting your customers' details.
  • Staff PINs for clocking in are stored as hashes, and five wrong tries lock the PIN for 15 minutes. Credit sales over a customer's limit need a manager to confirm with their own password.

For how AI, cash-up and tills fit into running the business safely, see our guides on AI for small business and the end-of-day cash-up.

Questions people ask

What happens if someone keeps guessing my password?

After 5 wrong passwords or codes, the account is locked for 15 minutes. Repeated failures from one internet address also get that address blocked from signing in, for a day by default.

I lost my phone with the authenticator app. How do I get in?

Use one of the 10 backup codes you were given when you set up two-step sign-in. Each works once. An admin in your business can also reset your two-step sign-in, which signs you out everywhere and emails you.

Does signing out on one device sign me out everywhere?

Yes. Signing out, changing your password or resetting it ends all of your sessions on every device, not just the one in front of you.

Can I see who changed a price or a customer record?

Yes. Admins, owners and managers can open Settings, then Activity, and filter by area, person and time to see each change written as a plain sentence.

How long are backups kept?

The backup routine keeps the last 30 daily copies, then one copy a week for 12 weeks, one a month for 12 months and one a year for 5 years.

Can I limit what a member of staff sees?

Yes. Each person has a role, and an admin or owner can decide which parts of EasyTaskr each role or person can open from the permissions settings.