IT Security
Last Updated: September 14, 2026
MoreTasks (“the Company,” “we,” or “us”) treats the security of client and company information as core to how we operate. This IT Security page summarizes the safeguards, controls and practices we maintain to protect data across our systems, facilities and people.
As an outsourcing partner, we can process information on behalf of clients under their instructions and applicable agreements. Where a client agreement or statement of work specifies particular security requirements, those requirements apply in addition to the practices described here.
Our Approach to Information Security
We maintain a layered security program spanning governance, technical controls, physical safeguards and workforce practices, designed to protect the confidentiality, integrity and availability of information we handle.
Our practices are informed by internationally recognized information security frameworks and are reviewed periodically as our operations, client requirements and the threat landscape evolve.
Information Security Governance
Security responsibilities are assigned across our organization, with defined ownership for policy, risk management and day-to-day operational controls.
- Documented information security policies covering acceptable use, data handling, access management and incident response;
- Periodic risk assessments to identify and address security gaps;
- Defined escalation paths for security-related decisions and exceptions; and
- Regular review of policies and controls to reflect changes in our systems and operating environment.
Data Protection & Encryption
We apply technical safeguards intended to protect information in transit and at rest, including the use of encryption for sensitive data where appropriate, and controls designed to limit the exposure of information outside authorized systems and personnel.
Where we process personal information, these safeguards work alongside the practices described in our Privacy Policy.
Access Control & Identity Management
Access to systems and information is granted on the basis of business need and role, and is subject to ongoing review.
- Unique user credentials and authentication requirements for access to systems handling client or company data;
- Multi-factor authentication for access to sensitive systems, where applicable;
- Role-based access controls limiting access to what is required for a given function; and
- Prompt revocation of access upon role change or separation from the Company.
Network & Infrastructure Security
We maintain controls designed to protect our network perimeter and internal systems, including firewalls, network segmentation, and monitoring of systems for unauthorized activity.
Software and systems are maintained with a view to applying security updates and patches in a reasonably timely manner, and vulnerabilities identified through internal review or external reporting are assessed and addressed based on severity.
Endpoint & Device Security
Company-managed devices used to access client or company systems are subject to baseline security controls, including endpoint protection tools, device configuration standards and requirements for secure storage and disposal of equipment.
Physical Security
Our facilities apply physical access controls intended to restrict entry to authorized personnel and visitors, including access management at facility entry points and monitoring of workspaces where client or company data is handled.
Security Monitoring & Incident Response
We maintain processes to monitor for, identify, and respond to potential security events affecting our systems or information.
In the event of a confirmed security incident affecting personal information or client data, we follow internal procedures to assess, contain, and remediate the incident, and to provide notification where required by law or applicable client agreements.
Employee Security Awareness & Training
Employees and contractors with access to Company or client systems are required to follow applicable security policies. We provide security awareness training designed to help our workforce recognize common risks, such as phishing and social engineering, and to reinforce responsible data handling practices.
Personnel with access to sensitive client environments can be subject to additional confidentiality obligations and role-specific training as required by the relevant engagement.
Third-Party & Vendor Security
Where we engage service providers or technology vendors that can access or process information on our behalf, we take reasonable steps to assess their security practices and require appropriate contractual safeguards, including confidentiality and data protection obligations consistent with this page and our Privacy Policy.
Client Data Segregation
Where our engagements involve handling information on behalf of multiple clients, we apply logical and, where required, physical separation designed to prevent unauthorized access between client environments, consistent with the terms of the relevant client agreement.
Business Continuity
We maintain processes intended to support the continuity of critical operations in the event of a disruption, including backup practices for critical systems and data, and periodic review of continuity arrangements.
Reporting a Security Concern
If you believe you have identified a security vulnerability or concern affecting MoreTasks systems, please contact us using the details below so that we can investigate. We ask that you avoid accessing, modifying or exfiltrating data beyond what is necessary to demonstrate an issue, and that you report the matter to us before any public disclosure.
Changes to This Page
We can update this IT Security page periodically to reflect changes in our practices, systems or applicable requirements. When we make changes, we will update the “Last Updated” date at the top of this page.
Contact Us
If you have questions about our IT security practices or wish to report a security concern, please contact us:
- Email: contact@moretasks.com
- Phone number: +91 124 437 7022