Security
Security practices designed to give teams clarity at every layer of the platform.
Gravitask is built to keep project data private, permissions understandable, and infrastructure manageable as teams grow.
UK-hosted infrastructure
Gravitask runs on Microsoft Azure infrastructure and is configured for UK hosting so teams can keep work management data close to home.
Encrypted transport and managed secrets
Traffic is served over HTTPS, and application secrets are managed through Azure Key Vault instead of being baked into client code.
Workspace-aware permissions
Projects, memberships, and collaboration features are scoped to workspaces so teams can share what they need without exposing everything.
AI agent governance
Every MCP agent action is attributed, auditable and reversible. Scope agents and connected clients to specific tools, cap permission levels, add rate limits and IP allowlists, and require approval for sensitive writes.
What this means in practice
Application controls
Authentication, workspace membership, project sharing, task collaboration, and billing access all flow through scoped application permissions instead of one flat access model.
Operational controls
Supporting services such as email delivery, blob storage, and hosted application workloads are kept behind managed Azure infrastructure and deployment pipelines.
Governing AI agents
Gravitask gives every tier full read/write access for AI agents over MCP, and keeps that access accountable. Control is what the Business plan sells, not capability.
Attribution, preview and undo
Every agent write is labelled with the client that made it and the person it acted for, can be previewed before it commits, and can be reverted, one change or a whole session at a time.
Approvals and access controls
Route sensitive writes to a human for approval, scope each agent or client to specific tool groups and permission levels, add per-key rate limits and IP allowlists, and set org-wide policy defaults new workspaces inherit.
Audit trail and SIEM export
Every agent tool call and change is recorded. Export the MCP audit trail to CSV for compliance archives, or stream it to your SIEM in real time over webhooks.
Kill switches
Disable individual MCP tools, lock whole tool groups across the organisation, and revoke any connected client or agent identity the moment you need to.