Zero-knowledge
We do not hold the client keys needed to decrypt readable workspace content
$0 Free tier
No credit card required
500+ professionals
Trusted by privacy-focused teams
Quick verdict.
Choose SealTask when sensitive task, note, comment, checklist, and attachment content should be encrypted before sync and unavailable to the provider. Before any PHI use, SealTask must expressly agree in writing. Where HIPAA applies, SealTask and the customer must execute a HIPAA-compliant BAA before use. Choose Basecamp when you want projects to combine to-dos, message boards, chat, schedules, files, automatic check-ins, client access, and broad project history in one conventional cloud workspace.
Feature comparison.
| Feature | SealTask | Basecamp |
|---|---|---|
| End-to-End Encryption | ||
| Zero-Knowledge Architecture | ||
| Self-Hosted Deployment Option | ||
| Provider Can Access Workspace Content | ||
| Free Tier | ||
| GDPR Support | ||
| Open Source Crypto | ||
| Data Export | ||
| Team Collaboration | ||
| Kanban Boards | ||
| Rich Text Editing | ||
| Time Tracking | Timesheet is included with Pro Unlimited; Basecamp lists it as an optional $50/month flat upgrade on Pro. | |
| Calendar & Reminders | ||
| Granular Team Activity Logs | ||
| Starting price | €0; Personal €5.90/mo; Team €4.90/seat/mo | Free for 1 project; Pro $15/user/mo; Pro Unlimited $299/mo annually |
Want the private option?
Try SealTask in the hosted cloud, or talk to us about the licensed self-hosted Docker image for your own hardware.
Who should choose which?
Choose SealTask if...
- You handle sensitive client or internal project data
- You need strong encryption for regulated workflows
- You do not want server-side AI processing workspace content
- You prefer focused task management over a broad work OS
- You want the provider unable to read encrypted content
- You want a licensed self-hosted Docker option on your own hardware
Choose Basecamp if...
- You want messages, chat, files, schedules, and to-dos in every project
- Client access and centralized project communication are central
- Automatic check-ins, reports, and project history matter
- A fixed unlimited-user price fits your organization
- You are comfortable with provider-operated cloud access controls
Security architecture.
SealTask: zero-knowledge.
SealTask encrypts readable workspace content on your device with ChaCha20-Poly1305 before sync. The client unlocks keys with an OPAQUE export key plus HKDF, and optional one-time backup keys stay user-held. The service does not hold the keys needed to decrypt that content; account and operational metadata remain server-visible.
Result: A database breach or legal demand can expose ciphertext and server-visible account, billing, security, audit, service, and workspace metadata. SealTask cannot decrypt readable workspace content without the client-held keys.
Basecamp: encrypted cloud storage with provider-operated access.
37signals says Basecamp uploads are encrypted at rest with AES-256 and backup files are encrypted with GPG. For Basecamp 5, it says every database field containing customer-generated content is encrypted with a unique per-field key, and those keys are encrypted with a master key—its “at-work” encryption design. It separately states that application databases as a whole are not encrypted at rest. These are provider-operated controls, not client-side zero-knowledge encryption.
Result: Because Basecamp operates the application and keys, authorized service workflows can access project content. The linked 2019 record is separately classified as credential stuffing: Basecamp said reused third-party credentials were used and its own systems were not compromised.
Frequently asked questions.
Is Basecamp end-to-end encrypted?
No. Basecamp publishes encryption at rest and in transit, but not SealTask-style client-side end-to-end encryption. That means the service can process workspace content in plaintext for product features and authorized support workflows.
Can Basecamp employees see my data?
Basecamp publishes access controls and policies limiting employee access, but its architecture still permits authorized server-side access to workspace content. With SealTask's zero-knowledge architecture, even our engineers cannot access encrypted workspace content because we do not have the keys.
Can I use Basecamp or SealTask for HIPAA-regulated PHI?
Do not treat either product as HIPAA-ready by default. SealTask's zero-knowledge design may help with technical safeguards. Before any PHI use, SealTask must expressly agree in writing. Where HIPAA applies, SealTask and the customer must execute a HIPAA-compliant BAA before use. Basecamp does not publish a standard HIPAA or BAA offering on its public pricing or security pages.
When should I choose Basecamp instead of SealTask?
Choose Basecamp when a project should combine team messages, chat, documents, schedules, check-ins, reporting, and client participation. Choose SealTask when focused task collaboration and client-side encrypted workspace content are the more important requirements.
Explore private Basecamp alternatives
Researching Basecamp's security history?
We maintain a dated, source-linked record of publicly documented Basecamp security incidents — what happened, who was affected, and how the vendor responded.
Read the Basecamp incident recordComparing for a specific kind of private work?
The guide library adds audience-specific workflows, metadata caveats, and system-of-record decisions for legal, people, executive, startup, consulting, and private-practice work.
Browse audience guidesReferences.
- 01 Basecamp pricing - Official Free, Pro, and Pro Unlimited pricing and plan limits
- 02 Basecamp features - Official project, communication, reporting, and collaboration feature inventory
- 03 37signals security overview - Official distinction between encrypted uploads and backups, unencrypted whole application databases, and per-field/master-key “at-work” encryption for every Basecamp 5 database field containing customer-generated content
- 04 SealTask security architecture - Zero-knowledge encryption details
- 05 RFC 8439: ChaCha20-Poly1305 - Encryption standard used by SealTask
Need private tasks before all-in-one project communication?
Start on the Free tier, or ask about the licensed self-hosted Docker distribution for your own hardware.
Start free