Source
Security page — Todoist
Checked for Todoist on 16 Sep 2026
- Page
- https://www.todoist.com/security
- Checked
- 16 Sep 2026, 03:43 UTC
- How we may use it
- Public page, crawling permitted
Technical details
- type
- page
- http status
- 200
- content hash
- sha256:90a2eb7486efe93769aed6d6378b9c03b6f0bb74d84a73ba518f138e705f3b95
- permission
- robots_ok
- screenshot
- Screenshot on file (internal exhibit, not published)
Cited by
Facts read from this source
-
Encryption in transit Report an error
“we use TLS 1.2 and 1.3 secure channels and support both 128-bit or 256-bit configurations, depending on the browser”
-
Provider Report an error
“We use Amazon Web Services (AWS) servers to host all user data”
-
File encryption cutoff Report an error
“All files uploaded after April 11, 2016 are stored and encrypted at rest”
-
Aws certifications Report an error
“AWS data centers undergo annual certifications to ensure they meet the highest standards of physical and virtual security.”
-
Backup Report an error
“All user data are automatically backed up on AWS servers with multiple redundant copies.”
-
App backup frequency Report an error
“Additionally, Todoist creates automatic backups within the app on a daily basis. You can also create a backup at any time.”
-
Backup recovery Report an error
“These backups can be accessed in Account Settings and can be used to recover data for any project or task.”
-
Bug bounty Report an error
“Our bug bounty policy covers the program rules, eligible targets, rewards, and severity levels.”
-
Authentication Report an error
“We verify account access through both email/password-based authentication and Google Accounts authentication via OAuth 2.0.”
-
Password storage Report an error
“we always store individual passwords with unique salts to add an extra layer of protection to your account.”
-
Business admin roles Report an error
“For Todoist Business accounts, we provide two different user roles and access privileges: admin and user.”
-
Business admin controls Report an error
“Account administrators have access to the central control panel to manage billing information, users, and sharing settings.”
-
Business sharing settings Report an error
“Sharing Settings allows the administrator to choose between restricting sharing to only employees within the organization or allowing sharing outside of the organization (e.g., with clients, vendors, etc.).”
-
Privacy policy Report an error
“Please see our full privacy policy for more details.”
-
GDPR Report an error
“Visit our trust center to learn more about how we handle your personal information, the security measures we implement, and our compliance with global regulations like the GDPR.”
-
Third party attachments Report an error
“All data included in Dropbox and Google Drive attachments remain on those companies’ servers and are covered by their respective security policies and practices.”
-
Report vulnerability Report an error
“If you discover any security vulnerability in Todoist, please submit a report and we'll do our best to fix it right away.”
Scores citing this record
- The Bootstrapper Collaboration depth
- The Bootstrapper Integrations
- The Bootstrapper Onboarding effort
- The Bootstrapper Support & documentation
- The Bootstrapper Collaboration depth
- The Bootstrapper Integrations
- The Bootstrapper European sovereignty
- The Bootstrapper Support & documentation
- The Bootstrapper Collaboration depth
- The Bootstrapper European sovereignty
- The Data Protection Officer Collaboration depth
- The Data Protection Officer Integrations
- The Data Protection Officer European sovereignty
- The Data Protection Officer Support & documentation
- The Data Protection Officer Collaboration depth
- The Data Protection Officer Integrations
- The Data Protection Officer European sovereignty
- The Data Protection Officer Support & documentation
- The Data Protection Officer Collaboration depth
- The Data Protection Officer European sovereignty
- The Enterprise Architect Collaboration depth
- The Enterprise Architect Integrations
- The Enterprise Architect Onboarding effort
- The Enterprise Architect European sovereignty
- The Enterprise Architect Support & documentation
- The Enterprise Architect Collaboration depth
- The Enterprise Architect Integrations
- The Enterprise Architect European sovereignty
- The Enterprise Architect Support & documentation
- The Enterprise Architect Collaboration depth
- The Enterprise Architect European sovereignty
- The Integrator Collaboration depth
- The Integrator Integrations
- The Integrator Support & documentation
- The Integrator Collaboration depth
- The Integrator Integrations
- The Integrator Support & documentation
- The Integrator Collaboration depth
- The Integrator European sovereignty
- The Skeptic Collaboration depth
- The Skeptic Integrations
- The Skeptic European sovereignty
- The Skeptic Collaboration depth
- The Skeptic Integrations
- The Skeptic European sovereignty
- The Skeptic Support & documentation
- The Skeptic Collaboration depth
- The Skeptic European sovereignty
- The UX Purist Collaboration depth
- The UX Purist Integrations
- The UX Purist European sovereignty
- The UX Purist Support & documentation
- The UX Purist Collaboration depth
- The UX Purist Integrations
- The UX Purist European sovereignty
- The UX Purist Support & documentation
- The UX Purist Collaboration depth
- The UX Purist European sovereignty