Trust center · Updated July 30, 2026
Security
The identity wall, payment gate and quality review are enforced at the data and transaction layers—not only hidden in the interface.
Access and identity
Every protected read and mutation rechecks the signed-in user, role and resource ownership. Password accounts must verify their email. Workers lose task-file access as soon as a task leaves their hands or their approval is suspended.
Files
Uploads are size-limited, signature-checked, hashed and unavailable until scanning passes. Office documents with macros, external relationships, comments, hidden sheets or embedded objects are refused. Common author metadata is removed from Office and image files. Production scanning fails closed when the malware service is unavailable.
No automated system can remove identifying information written into the visible content itself. Clients and workers must remove names, contacts and account identifiers before upload; the operator performs a second content review before release.
Payments and audit
Card details are collected by Stripe. A task cannot reach the worker pool until a signed webhook confirms the approved amount. State changes, payouts, refunds and administrative decisions are recorded with idempotency controls and database-enforced invariants.
Reporting
Report a suspected vulnerability to security@afterdesk.co. Do not access other users’ data or disrupt the service while testing.