A four-stage client workflow

Secure task management for consultants.

A consultant’s task list can expose the client, the problem, the fee pressure, the internal sponsor, the delayed decision, and the recommendation before the deliverable exists.

Use SealTask for the encrypted operational sequence. Keep contracts, research data, source documents, regulated records, credentials, invoices, and final deliverables in their authoritative systems.

Last reviewed

Short answer.

SealTask can coordinate owners, dependencies, reviews, and closeout steps for an approved engagement. Keep contracts, client data, source documents, credentials, working papers, invoices, and deliverables in their authoritative systems. Task content is encrypted before sync, while timing, membership, status, relationships, and other operational metadata remain server-visible.

Why a separate task layer?

A CRM records the relationship. A document system stores deliverables. Time and billing tools record commercial work. The day-to-day sequence between those systems often becomes a readable checklist elsewhere.

The client name may be confidential.

A public-sector tender, restructuring, security review, acquisition, investigation, or product launch can be sensitive before any substantive task detail appears.

Every engagement creates temporary access.

Subcontractors and client collaborators need a scoped workstream for a defined period. They do not need a consultant’s other clients or complete practice backlog.

Deliverables outlive the task that produced them.

The formal output needs versioning, approval, retention, and client handoff in a document or client system. A completed task is not the deliverable record.

What does the service know about an engagement?

SealTask cannot decrypt readable workspace content, but it can see the operational metadata required to run the service.

Unreadable to the service

  • Readable task titles
  • Readable task bodies and notes
  • Readable recurring-task template content
  • Readable comment bodies
  • Readable checklist content
  • Readable project titles and descriptions
  • Attachment plaintext
  • Plaintext account passwords
  • Workspace content decryption keys

Server-visible workspace metadata

  • Account email addresses and workspace or project membership identities, roles, statuses, invitation states, and access timestamps
  • Database identifiers and relationships, including project owner, task and note creators, comment authors, delegation members, attachment uploaders, and per-member task-read cursors
  • Project timezone, section identifiers and policies, section timestamps, and task position or order
  • Task priority, completion and archive state and timing; note privacy and timestamps; per-member task-read timestamps; project timestamps and archive state; note, comment, and attention counts; and workspace write or collaboration entitlement flags
  • Recurrence schedule, timezone, active state, section, iteration, next-run, last-materialized, and task-materialization timestamps
  • Comment authorship relationships, counts, and timestamps; comment bodies remain encrypted
  • Delegation membership identifiers, roles, statuses, and timestamps; delegation notes remain encrypted
  • Attachment, project, and task relationships, including task-to-attachment link timestamps; storage identifiers; ciphertext byte size (which usually approximates original file size); upload capability expiry and protocol; status; and creation, update, or deletion timestamps; attachment content remains encrypted
  • Per-membership salts and membership proofs, plus the server-held project-scoped payload-binding key used to verify or compute matching HMACs; this binding key is not a workspace-content decryption key
  • Real-time event types; event, project, actor, membership, browser-instance, affected entity, section, and order identifiers; changed-field names; occurrence timestamps; and missed-event counts

This disclosure covers encrypted workspace content and its server-visible metadata. The workspace-content metadata inventory is complete for the enumerated current workspace persistence and SQL models, API-response models, and SSE event models. It is not a complete privacy-data inventory and excludes account authentication, billing, security and audit, abuse-prevention, and service telemetry domains; those domains are described non-exhaustively in the privacy policy. Metadata can itself be sensitive. Attachment ciphertext size usually reveals an approximation of the original file size.

A deadline may reveal a transaction, regulatory response, launch, or board event. Use neutral timing or the client’s approved system where metadata itself is sensitive.

Inspect the security architecture

Worked example: a two-week discovery sprint.

The engagement is identified internally as C-31. The task layer coordinates evidence collection without becoming the evidence repository.

SealTask

C-31: confirm interview owner for operations.

A neutral engagement reference and next action are enough for the coordination list.

SealTask

C-31: record whether the process-map request is complete.

Completion state lives in SealTask; the process map stays in the client repository.

Specialist system

Interview recording, transcript, and participant details.

Store these only in the approved research or client system with the required notice and retention handling.

Specialist system

Client export, credentials, working papers, and final deck.

Use approved client storage, a password manager, and the document-management system.

The task list answers who does what next. The evidence base answers how the conclusion was reached.

Coordination versus the client record.

Client contracts and sector rules may narrow these defaults further. Treat this as a starting decision model, not permission.

Work item SealTask System of record Why
Owner, next action, dependency, and review gate Yes — after client and firm approval Project, CRM, or document system SealTask coordinates the engagement while formal records remain authoritative elsewhere.
Signed proposal, SOW, NDA, and change order Reminder only Contract system or CRM Commercial and legal terms require authoritative versions and retention.
Client data exports, research data, transcripts, and evidence No — do not duplicate Approved client or research repository Source data needs purpose, access, retention, and deletion controls.
Credentials, API tokens, and recovery codes No Password or secrets manager A task manager is not a credential vault.
Subcontractor delivery workstream Yes — dedicated shared list Approved engagement systems Per-list access narrows coordination; source-system access is separately governed and revoked.
Time, expenses, invoice, and tax records Prompt only Time, expense, accounting, and tax systems Financial records need specialist reporting and retention.

The engagement, from first scope to final closeout.

Each stage has an operational list and a boundary. The sequence is useful precisely because it does not absorb every source document.

  1. 01 · 1.0 · Scope

    Turn the proposal into an owned start.

    Track conflict or independence checks, contract owner, kickoff prerequisites, and the first decision. Keep the signed agreement, pricing model, and legal terms in the CRM or contract system.

    ExampleEngagement C-31: confirm kickoff prerequisites with sponsor.

  2. 02 · 2.0 · Discover

    Coordinate interviews and evidence collection.

    Use tasks for interview scheduling, owner follow-up, and evidence requests. Keep recordings, transcripts, personal data, client exports, and research evidence in the approved repository.

    ExampleC-31: confirm owner for the outstanding process map.

  3. 03 · 3.0 · Deliver

    Move analysis through review and decision.

    Track draft ownership, review gates, dependencies, and client decisions. Keep working papers and deliverables in the document system with authoritative versions.

    ExampleC-31: route recommendation draft for internal challenge.

  4. 04 · 4.0 · Close

    Revoke, archive, invoice, and learn.

    For a fixed-term engagement, optionally set the agreed closeout as the invitation’s access-end date; leave it unset when access should continue until manual removal. During offboarding, Access review lists each subcontractor’s engagement projects and last activity. Remove the departing person from every client project you manage, then separately revoke client portals and other source systems before recording handoff, invoice, retention, and review evidence. Once the engagement is closed, archive its SealTask project so the encrypted history remains readable but cannot be changed; restore it only if the engagement formally reopens.

    ExampleC-31: verify access removal, record handoff, and archive the project.

Product fit for a one-person practice or small firm.

The Free tier covers a private solo operating list. Personal adds the per-list collaboration needed for a client or subcontractor handoff.

Recurring tasks without recurring plaintext

Set repeating operational work once. The task content stays encrypted on the client before sync; due dates and recurrence timing remain operational metadata.

One shared list, not blanket access

Personal (€5.90/month) adds per-list sharing. Invite a collaborator only to the list they need. Removing a collaborator revokes their server-authorized access to the project. Using access review to remove them from every manageable project applies that same server-side revocation to each project. On the server that commits the change, active real-time streams are signaled after the commit; changes committed on another server and bulk or otherwise unsignaled changes are rechecked within the current authorization lease, at most 30 seconds. Bytes already delivered or buffered by the transport cannot be recalled. The current release does not automatically rotate any affected project key or re-encrypt projects for remaining members, and removal cannot erase content or key material obtained while the collaborator was authorized. If future sensitive work needs a fresh cryptographic boundary, create a new project and share it only with current members.

Private search on the device

Search runs after local decryption in the browser. SealTask does not need a readable server-side search index of workspace content.

A €0 solo starting point

Free includes one workspace, two projects, 100 MB of encrypted attachments, and 30-day audit history. No credit card is required.

Secure tasks do not make an engagement compliant.

SealTask is not a CRM, client portal, document-management system, virtual data room, time tracker, accounting product, tax system, research repository, consent platform, records-retention engine, or secrets manager.

SealTask is not currently SOC 2 certified; accounts can add optional authenticator-app two-factor authentication (TOTP) with one-time backup codes. Consultants should assess client contracts, confidentiality duties, professional standards, sector rules, device controls, subcontractors, retention, incident response, cross-border processing, and client-approved tooling.

Tax, financial, health, legal, public-sector, defense, and other regulated engagements may require controls or agreements beyond SealTask’s current offering. Do not infer a BAA, regulatory approval, or certification from end-to-end encryption.

Questions this guide should answer.

Can I give a client access to one engagement?

Paid plans support per-list sharing. Create a dedicated engagement list, confirm the client is authorized to use it, and keep contracts, source data, and deliverables in the approved systems.

Can SealTask staff read client names in tasks?

SealTask cannot decrypt readable task, project, note, comment, checklist, recurring-template, or attachment content, and it does not receive plaintext passwords or workspace content keys. The service can still see operational metadata such as account and membership identities, relationships, task state and timing, recurrence schedules, attachment sizes and statuses, and real-time event identifiers. Metadata can itself be sensitive; the security architecture lists the complete current workspace inventory.

Can I store client credentials in an encrypted task?

Do not. Use an approved password or secrets manager. Encryption does not give a task product the controls or lifecycle of a credential vault.

Is SealTask suitable for tax or financial client data?

Do not assume so from this guide. Tax and financial practices can have specific legal, contractual, security-plan, authentication, incident, and vendor requirements. Assess those requirements and obtain appropriate advice before use.

What happens when a subcontractor leaves?

Removing a collaborator revokes their server-authorized access to the project. Using access review to remove them from every manageable project applies that same server-side revocation to each project. On the server that commits the change, active real-time streams are signaled after the commit; changes committed on another server and bulk or otherwise unsignaled changes are rechecked within the current authorization lease, at most 30 seconds. Bytes already delivered or buffered by the transport cannot be recalled. The current release does not automatically rotate any affected project key or re-encrypt projects for remaining members, and removal cannot erase content or key material obtained while the collaborator was authorized. If future sensitive work needs a fresh cryptographic boundary, create a new project and share it only with current members. Revoke access in every source system separately.

Sources and further reading.

  1. 01

    SealTask security architecture Open page Encryption, key handling, server visibility, and recovery tradeoffs

  2. 02

    SealTask pricing Open page Current Free, Personal, Team, and self-hosted terms

  3. 03

    Best encrypted task management Open page A source-backed comparison of encryption models and product tradeoffs

  4. 04

    FTC — Protecting Personal Information: A Guide for Business Open source Minimize collection and retention, use least privilege, protect what remains, and dispose securely

  5. 05

    NIST SP 800-171 Rev. 3 — Least Privilege Open source Access should be limited to what is necessary for assigned organizational tasks

  6. 06

    IRS — Protect your clients; protect yourself Open source Current security-plan and client-data guidance for tax professionals

Run the engagement without exposing the running list.

Start solo on Free. Add a client or subcontractor only through a dedicated list with an explicit content boundary.