{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "taiga",
    "name": "Taiga",
    "vendor": "Taiga Cloud Services, S.L.",
    "vendorUrl": "https://taiga.io",
    "kind": "http-api",
    "category": "project-management",
    "summary": "Taiga is open-source agile project management software with Scrum backlogs, Kanban boards, issues and a wiki, hosted at tree.taiga.io or self-hosted. Agents reach it through a REST API at `api.taiga.io/api/v1`.",
    "url": "https://www.anchorterminal.com/tools/taiga",
    "markdownUrl": "https://www.anchorterminal.com/tools/taiga.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/taiga.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/taiga.json",
    "repo": "https://github.com/taigaio/taiga-back",
    "license": "MPL-2.0 for the taiga-back source. The hosted service runs under Taiga's Terms and Conditions, which also mention non-open-source modules",
    "transports": [
      "http"
    ],
    "packages": [],
    "auth": "mixed",
    "authNotes": "Access is self-serve with a Taiga account, and there is no API key or personal token. A client posts the account's user name and password to `/api/v1/auth` and receives a bearer token and a refresh token. The backend's default lifetimes are 24 hours and 8 days. The token acts with the user's permissions in each project and has no scopes. The docs also describe application tokens, sent as `Authorization: Application \u003ctoken\u003e`, for an application an instance administrator has registered. No way to register an application on the hosted service was found. No app review or partner approval is described.",
    "pricing": "freemium",
    "pricingNotes": "The hosted Free plan has one public and one private project and 10 MB of storage, and the terms say API access is free, so an agent can start without a contract. Paid hosted plans are a flat monthly price with unlimited users, Enthusiast 5 euros (50 a year), Basic 20 euros (200 a year) and Premium 60 euros (600 a year). Private cloud and on-premise support are by quote. The software is free to self-host. API calls are not priced, and prices are in euros only (https://taiga.io/deployment-pricing-options/, checked 2026-10-09).",
    "priceSummary": "Freemium",
    "where": "local",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the API reference, the pricing page or the terms (checked 2026-10-09).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 858,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-09"
    },
    "docsUrl": "https://docs.taiga.io/api.html",
    "capabilities": [
      "tasks.create",
      "tasks.update",
      "projects.manage",
      "tasks.comments",
      "projects.reporting",
      "events.webhooks-send"
    ],
    "tags": [
      "official",
      "hosted",
      "self-hosted",
      "open-source",
      "rest",
      "freemium",
      "free-tier",
      "webhooks",
      "eu-hosting",
      "project-management"
    ],
    "lastRelease": "2026-07-02",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 31.7,
      "grade": "F",
      "agentReady": false,
      "rank": 830,
      "ranked": true,
      "rankOf": 842,
      "categoryRank": 14,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 49,
        "maintenance": 21,
        "payments": 30,
        "reliability": 17,
        "schema": 35,
        "security": 37,
        "transparency": 64
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 17,
          "points": 3.4,
          "reason": "Graded on the hosted REST API at api.taiga.io, with the hosted lines. The same API ships in the open-source backend. No status page is linked from the site, the docs or the terms (0), so there is no incident record to read (0). No request limit is published with numbers. The reference says only that an instance configured with throttling answers 429, and the backend's default settings leave the general rates unset (2 of 15). The backend's 429 message states the seconds to wait, which the reference does not mention, and every modifying request carries a `version` for optimistic concurrency. No idempotency keys and no retry guidance (5 of 15). The pricing page names priority support with an SLA for on-premise contracts by quote, and no SLA text is published (0). The API is version 1 and runs the vendor's own web client, though the terms say it may not always be available (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 35,
          "points": 5.69,
          "reason": "No OpenAPI or other machine-readable contract was found (0). No llms.txt (the path returned 404). The docs' AsciiDoc source is public in taigaio/taiga-doc but is not served to agents (2 of 10). Each of the 49 sections states what a call does and lists its parameters in a line or two, with nothing on when not to use it (10 of 20). Parameters are listed with a type and a required mark, with no schema, enumerations or constraints (6 of 15). Every call has a curl example and a sample response object. Error responses are not described (9 of 15). The version sits in the path and the backend has a dated changelog. There is no changelog for the API, and the reference's footer is dated 3 April 2024 (8 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 49,
          "points": 7.96,
          "reason": "Graded on the REST API. Lists return 30 items a page and use lighter list objects than the detail calls. There is no field selection, and the page-size parameter in the backend settings is not in the reference (12 of 25). Pagination headers, per-resource filters, `order_by`, a `filters_data` call for each work item type and a project search endpoint (16 of 20). The backend returns `_error_message` and `_error_type` fields, which the reference does not document (6 of 20). No idempotency keys. The `version` parameter stops lost updates (10 of 20). No official SDK was found. Creating a task needs only a project and a subject, and a resolver call turns slugs into ids (5 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 37,
          "points": 6.48,
          "reason": "The hosted service has no API key. A client posts the account's user name and password to `/api/v1/auth` and gets a bearer token, 24 hours by the backend default, with an 8-day refresh token. The token has no scopes and travels in the Authorization header. Application tokens need an application registered by an instance administrator (10 of 30). Reach is set by project roles with per-permission lists, so a dedicated account with a narrow role is the least-privilege route. No read-only token and no confirmation step for deletes (10 of 20). Story, issue and wiki text is untrusted content, and no prompt-injection guidance was found (2 of 15). Each object has a history endpoint, projects have timelines and webhooks have a delivery log. No API access log was found (7 of 15). A SECURITY.md and a security page give security@taiga.io, and two advisories with CVEs were published in October 2025. No security.txt, no bug bounty and no certificate held by Taiga were found. The security page cites the hosting provider's ISO/IEC 27001 (8 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 30,
          "points": 3.75,
          "reason": "No x402, MPP or L402 (0). Plan prices are public, flat per month in euros with unlimited users, 5, 20 and 60 euros. API calls are not priced (10). A Free plan with one public and one private project and 10 MB of storage. We did not open the registration form, so no card is our reading of the pricing page (20). The reference documents `POST /api/v1/auth/register`, which takes an email address, a password and acceptance of the terms. We did not call it, the backend ships with public registration off, and a person accepting terms is still a signup, so no credit (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 21,
          "points": 1.84,
          "reason": "The latest tagged backend release is 6.10.2 of 2 July 2026, 99 days before the check (10). No tagged release in the last 90 days. The main branch had merges on 28 September 2026 and the changelog lists 6.10.3 as unreleased (0). Of the 25 open issues on the first page of taigaio/taiga-back, 18 have no reply, some since 2023, and 59 are open in all. The community forum was not sampled (6 of 25). No official SDK and no MCP server were found (0). One CI workflow runs the tests on Python 3.10 only, and issues about outdated packages (August 2025) and Python 3.13 (January 2026) are open. Version 6.10.0 updated dependencies (5)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 64,
          "points": 5.6,
          "note": "editorial 56, provenance 72",
          "reason": "The backend source is public under MPL-2.0. The hosted service runs under the Terms and Conditions of September 2025, which also refer to non-open-source modules without naming them (27 of 30). The privacy policy names two joint controllers and gives no retention period in numbers and no date. The DPA says deletion can take up to 90 days after the relationship ends, that no international transfers are foreseen and that breaches are notified within 48 hours. The privacy policy allows for transfers under standard contractual clauses, which sits loosely with the DPA (17 of 30). No deprecation policy. The terms say Taiga may modify or discontinue the API at any time with or without notice (2 of 20). The security page names the hosting provider and the Madrid data centre. No sub-processor list is published, and the DPA gives a general authorisation for sub-processors (10 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-09",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Graded on the REST API. Lists return 30 items a page and use lighter list objects than the detail calls. There is no field selection, and the page-size parameter in the backend settings is not in the reference (12 of 25). Pagination headers, per-resource filters, `order_by`, a `filters_data` call for each work item type and a project search endpoint (16 of 20). The backend returns `_error_message` and `_error_type` fields, which the reference does not document (6 of 20). No idempotency keys. The `version` parameter stops lost updates (10 of 20). No official SDK was found. Creating a task needs only a project and a subject, and a resolver call turns slugs into ids (5 of 15).",
          "maintenance": "The latest tagged backend release is 6.10.2 of 2 July 2026, 99 days before the check (10). No tagged release in the last 90 days. The main branch had merges on 28 September 2026 and the changelog lists 6.10.3 as unreleased (0). Of the 25 open issues on the first page of taigaio/taiga-back, 18 have no reply, some since 2023, and 59 are open in all. The community forum was not sampled (6 of 25). No official SDK and no MCP server were found (0). One CI workflow runs the tests on Python 3.10 only, and issues about outdated packages (August 2025) and Python 3.13 (January 2026) are open. Version 6.10.0 updated dependencies (5).",
          "payments": "No x402, MPP or L402 (0). Plan prices are public, flat per month in euros with unlimited users, 5, 20 and 60 euros. API calls are not priced (10). A Free plan with one public and one private project and 10 MB of storage. We did not open the registration form, so no card is our reading of the pricing page (20). The reference documents `POST /api/v1/auth/register`, which takes an email address, a password and acceptance of the terms. We did not call it, the backend ships with public registration off, and a person accepting terms is still a signup, so no credit (0).",
          "reliability": "Graded on the hosted REST API at api.taiga.io, with the hosted lines. The same API ships in the open-source backend. No status page is linked from the site, the docs or the terms (0), so there is no incident record to read (0). No request limit is published with numbers. The reference says only that an instance configured with throttling answers 429, and the backend's default settings leave the general rates unset (2 of 15). The backend's 429 message states the seconds to wait, which the reference does not mention, and every modifying request carries a `version` for optimistic concurrency. No idempotency keys and no retry guidance (5 of 15). The pricing page names priority support with an SLA for on-premise contracts by quote, and no SLA text is published (0). The API is version 1 and runs the vendor's own web client, though the terms say it may not always be available (10).",
          "schema": "No OpenAPI or other machine-readable contract was found (0). No llms.txt (the path returned 404). The docs' AsciiDoc source is public in taigaio/taiga-doc but is not served to agents (2 of 10). Each of the 49 sections states what a call does and lists its parameters in a line or two, with nothing on when not to use it (10 of 20). Parameters are listed with a type and a required mark, with no schema, enumerations or constraints (6 of 15). Every call has a curl example and a sample response object. Error responses are not described (9 of 15). The version sits in the path and the backend has a dated changelog. There is no changelog for the API, and the reference's footer is dated 3 April 2024 (8 of 15).",
          "security": "The hosted service has no API key. A client posts the account's user name and password to `/api/v1/auth` and gets a bearer token, 24 hours by the backend default, with an 8-day refresh token. The token has no scopes and travels in the Authorization header. Application tokens need an application registered by an instance administrator (10 of 30). Reach is set by project roles with per-permission lists, so a dedicated account with a narrow role is the least-privilege route. No read-only token and no confirmation step for deletes (10 of 20). Story, issue and wiki text is untrusted content, and no prompt-injection guidance was found (2 of 15). Each object has a history endpoint, projects have timelines and webhooks have a delivery log. No API access log was found (7 of 15). A SECURITY.md and a security page give security@taiga.io, and two advisories with CVEs were published in October 2025. No security.txt, no bug bounty and no certificate held by Taiga were found. The security page cites the hosting provider's ISO/IEC 27001 (8 of 20).",
          "transparency": "The backend source is public under MPL-2.0. The hosted service runs under the Terms and Conditions of September 2025, which also refer to non-open-source modules without naming them (27 of 30). The privacy policy names two joint controllers and gives no retention period in numbers and no date. The DPA says deletion can take up to 90 days after the relationship ends, that no international transfers are foreseen and that breaches are notified within 48 hours. The privacy policy allows for transfers under standard contractual clauses, which sits loosely with the DPA (17 of 30). No deprecation policy. The terms say Taiga may modify or discontinue the API at any time with or without notice (2 of 20). The security page names the hosting provider and the Madrid data centre. No sub-processor list is published, and the DPA gives a general authorisation for sub-processors (10 of 20)."
        },
        "sources": [
          {
            "what": "home page",
            "url": "https://taiga.io/",
            "seen": "2026-10-09"
          },
          {
            "what": "API reference",
            "url": "https://docs.taiga.io/api.html",
            "seen": "2026-10-09"
          },
          {
            "what": "deployment and pricing options",
            "url": "https://taiga.io/deployment-pricing-options/",
            "seen": "2026-10-09"
          },
          {
            "what": "Terms and Conditions, with section 13 on the API",
            "url": "https://taiga.io/terms-and-conditions/",
            "seen": "2026-10-09"
          },
          {
            "what": "privacy policy",
            "url": "https://taiga.io/privacy-policy/",
            "seen": "2026-10-09"
          },
          {
            "what": "Data Processing Addendum",
            "url": "https://taiga.io/data-processing-addendum-dpa/",
            "seen": "2026-10-09"
          },
          {
            "what": "security page",
            "url": "https://taiga.io/security/",
            "seen": "2026-10-09"
          },
          {
            "what": "about page",
            "url": "https://taiga.io/about-us/",
            "seen": "2026-10-09"
          },
          {
            "what": "backend repository, cloned (settings, changelog, SECURITY.md, CI workflow, throttling and history code)",
            "url": "https://github.com/taigaio/taiga-back",
            "seen": "2026-10-09"
          },
          {
            "what": "docs repository, cloned (API source, telemetry settings)",
            "url": "https://github.com/taigaio/taiga-doc",
            "seen": "2026-10-09"
          },
          {
            "what": "Docker deployment repository, cloned",
            "url": "https://github.com/taigaio/taiga-docker",
            "seen": "2026-10-09"
          },
          {
            "what": "security advisories, list and both advisories",
            "url": "https://github.com/taigaio/taiga-back/security/advisories",
            "seen": "2026-10-09"
          },
          {
            "what": "open issues, first page",
            "url": "https://github.com/taigaio/taiga-back/issues",
            "seen": "2026-10-09"
          },
          {
            "what": "one unauthenticated call to the hosted API (response headers)",
            "url": "https://api.taiga.io/api/v1/locales",
            "seen": "2026-10-09"
          },
          {
            "what": "security.txt, returned 404",
            "url": "https://taiga.io/.well-known/security.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "RDAP record for taiga.io",
            "url": "https://rdap.identitydigital.services/rdap/domain/taiga.io",
            "seen": "2026-10-09"
          }
        ],
        "openQuestions": [
          "unchecked: the registration form at tree.taiga.io, so whether the Free plan asks for a card and whether `POST /api/v1/auth/register` is open on the hosted service",
          "unchecked: the community forum at community.taiga.io, so responsiveness is scored on GitHub issues alone",
          "unchecked: the taiga-front repository and its licence. The licence line covers taiga-back",
          "Whether api.taiga.io applies request limits, and which. None is published",
          "Whether a hosted user can register an application for application tokens. The docs say applications are created in the Django admin",
          "When the hosted service received the fixes for CVE-2025-62368 and CVE-2025-62367",
          "Which modules the terms mean by non-open-source modules",
          "Whether a status page exists. None is linked from the site, the docs or the terms",
          "The lead was right about the product and the interface. Its vendor is Taiga Cloud Services, S.L., with Kaleidos as joint controller in the privacy policy"
        ]
      },
      "negative": -3,
      "negativeNotes": [
        "2025-10-28. Two advisories were published against taigaio/taiga-back, an authenticated remote code execution through unsafe deserialisation in the API, rated critical (CVE-2025-62368, CVSS 9.0), and a time-based blind SQL injection rated moderate (CVE-2025-62367). Both affect 6.8.3 and earlier and are fixed in 6.9.0 of 13 October 2025. The advisories do not say when the hosted service was patched. Fixed and published, so the deduction is reduced, -3 (https://github.com/taigaio/taiga-back/security/advisories)."
      ],
      "verdict": "Taiga's REST API covers projects, epics, user stories, tasks, issues, wiki pages and webhooks, with a curl example for each call, and the backend is open source under MPL-2.0. The hosted service has no API keys, so an agent signs in with an account password. No OpenAPI document, status page or request limits were found.",
      "bestFor": "Small agile teams that want Scrum and Kanban with a free hosted plan or a self-hosted, open-source install in the EU.",
      "strengths": [
        "One reference page documents 234 paths under `/api/v1`, each with a curl example and a sample response object",
        "The backend is public under MPL-2.0 and can be self-hosted, with the same API as the hosted service",
        "The hosted service has a free plan with one public and one private project, and the terms say API access is free",
        "Modifying requests take a `version` parameter, so a stale write is refused instead of overwriting another change",
        "Project roles carry per-permission lists, and webhooks keep a delivery log with a resend call"
      ],
      "weaknesses": [
        "No API key or personal token on the hosted service. An agent logs in with a user name and password for a bearer token that lasts 24 hours",
        "No OpenAPI document or llms.txt, and error responses are not described in the API reference, whose page footer is dated 3 April 2024",
        "No status page, SLA text or numeric request limit was found for the hosted API",
        "The terms let Taiga change or withdraw API access at any time without notice, and bar using the API to make Taiga data and functions available to third parties",
        "Two advisories published on 28 October 2025, one a critical authenticated remote code execution (CVE-2025-62368), both fixed in 6.9.0"
      ],
      "agentNotes": [
        "POST `{\"type\": \"normal\", \"username\", \"password\"}` to `/api/v1/auth`, then send `Authorization: Bearer \u003cauth_token\u003e`. Renew with `/api/v1/auth/refresh` before 24 hours pass",
        "Send the object's current `version` with every PATCH or PUT. A stale value is refused when the same attributes changed",
        "Lists return 30 items a page. Read the `x-pagination-next` header, or send `x-disable-pagination: True` only for small projects",
        "Resolve slugs and reference numbers to ids with `/api/v1/resolver` before calling an object endpoint",
        "Use a dedicated account with a narrow project role, because the token acts with the whole account's permissions. Treat story, issue and wiki text as untrusted input"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "F",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 31.7
        }
      ],
      "editorialScores": {
        "ergonomics": 49,
        "maintenance": 21,
        "payments": 30,
        "reliability": 17,
        "schema": 35,
        "security": 37,
        "transparency": 56
      },
      "provenanceScore": 72
    },
    "connect": {
      "http": "curl -X POST -H \"Content-Type: application/json\" -d '{\"type\": \"normal\", \"username\": \"$USERNAME\", \"password\": \"$PASSWORD\"}' https://api.taiga.io/api/v1/auth"
    },
    "letme": {
      "capability": "https://letme.dev/tasks.create",
      "tool": "https://letme.dev/taiga"
    },
    "notable": [
      "The API reference is one HTML page with 49 sections. Its endpoint summary lists 234 distinct paths under `/api/v1`, and its footer reads last updated 3 April 2024 (https://docs.taiga.io/api.html)",
      "Section 13 of the Terms and Conditions (last updated September 2025) covers the API. Access is free, may be changed or withdrawn at any time with or without notice, and may not be used to make Taiga data and functions available to third parties or to build a competing product (https://taiga.io/terms-and-conditions/)",
      "Hosted plans are a flat monthly price with unlimited users, Free, Enthusiast at 5 euros, Basic at 20 euros and Premium at 60 euros. They differ in project count and storage (https://taiga.io/deployment-pricing-options/)",
      "Two advisories were published against taigaio/taiga-back on 28 October 2025, an authenticated remote code execution rated critical (CVE-2025-62368, CVSS 9.0) and a time-based blind SQL injection rated moderate (CVE-2025-62367). Both are fixed in 6.9.0 (https://github.com/taigaio/taiga-back/security/advisories)",
      "The hosted service runs at AITIRE CLOUD in the Interxion MAD3 data centre in Madrid, Spain, and the DPA says no international transfers are foreseen (https://taiga.io/security/)",
      "The backend's default settings set every general throttle rate to none and turn anonymous telemetry on, sent to telemetry.taiga.io. Self-hosters switch it off with `ENABLE_TELEMETRY` (https://github.com/taigaio/taiga-back/blob/main/settings/common.py)",
      "The latest tagged backend release is 6.10.2 of 2 July 2026, which added a missing permission check. The main branch had merges on 28 September 2026 (https://github.com/taigaio/taiga-back/blob/main/CHANGELOG.md)"
    ],
    "area": "business",
    "details": [
      {
        "label": "Surface graded",
        "value": "The REST API of the hosted service at `https://api.taiga.io/api/v1`. The same API ships in the open-source backend for self-hosting"
      },
      {
        "label": "API",
        "value": "234 distinct paths in the reference's endpoint summary, covering projects, memberships, roles, milestones, epics, user stories, tasks, issues, wiki pages, history, search, stats, timelines, webhooks, importers and export. JSON over HTTPS. No OpenAPI document"
      },
      {
        "label": "Authentication",
        "value": "User name and password posted to `/api/v1/auth` for a bearer token (24 hours by the backend default) and a refresh token (8 days). Application tokens exist for applications an instance administrator registers"
      },
      {
        "label": "Rate limits",
        "value": "None published. The reference says an instance configured with throttling answers 429, and the backend's default settings leave the general read and write rates unset"
      },
      {
        "label": "Pagination and sizing",
        "value": "30 results a page by default, with `x-pagination-*` response headers and `x-disable-pagination: True` to turn it off. Per-resource filters and `order_by`. No field selection"
      },
      {
        "label": "Concurrency",
        "value": "Every modifying request sends the object's `version`. A stale version is refused when the same attributes changed"
      },
      {
        "label": "Comments",
        "value": "Added by sending a `comment` field when patching a story, task or issue (read in the backend source). The reference documents editing, deleting and restoring comments through the history endpoints"
      },
      {
        "label": "Webhooks",
        "value": "Created per project through `/api/v1/webhooks` with a key, plus a test call, a delivery log and a resend call"
      },
      {
        "label": "Hosted plans",
        "value": "Free (1 public and 1 private project, 10 MB), Enthusiast 5 euros a month (5 public and 5 private projects, 100 MB), Basic 20 euros (unlimited projects, 500 MB), Premium 60 euros (3 GB). Unlimited users on each"
      },
      {
        "label": "Hosting",
        "value": "AITIRE CLOUD in the Interxion MAD3 data centre, Madrid, Spain. The security page cites the provider's ISO/IEC 27001 and ENS certificates, not one held by Taiga"
      },
      {
        "label": "Security reports",
        "value": "security@taiga.io per the security page and SECURITY.md. No security.txt and no bug bounty found"
      },
      {
        "label": "Releases",
        "value": "taiga-back 6.10.2 on 2 July 2026, 6.10.1 on 6 May, 6.10.0 on 20 April, 6.9.0 on 13 October 2025"
      },
      {
        "label": "Telemetry (self-hosted)",
        "value": "Anonymous telemetry to telemetry.taiga.io is on by default and is switched off with `ENABLE_TELEMETRY=False`"
      }
    ],
    "unitPrices": [
      {
        "item": "Free (hosted)",
        "unit": "month",
        "usd": 0,
        "note": "1 public and 1 private project, 10 MB, unlimited users; paid plans are priced in euros (5, 20 and 60 a month)"
      }
    ],
    "provenance": {
      "legalEntity": "Taiga Cloud Services, S.L.",
      "domain": "taiga.io",
      "domainRegistered": "2013-12-04",
      "endpointOnVendorDomain": true,
      "terms": "https://taiga.io/terms-and-conditions/",
      "privacy": "https://taiga.io/privacy-policy/",
      "statusPage": "",
      "changelog": "https://github.com/taigaio/taiga-back/blob/main/CHANGELOG.md",
      "securityTxt": "none",
      "checked": "2026-10-09",
      "notes": [
        "The Terms and Conditions (last updated September 2025) name TAIGA CLOUD SERVICES, S.L., C/ Uruguay 15, Entreplanta B, 36201 Vigo, Spain. They cover the cloud and on-premise products, and section 13 covers use of the API. Spanish law governs.",
        "The privacy policy names two joint controllers, KALEIDOS INC SUCURSAL EN ESPAÑA S.L. and TAIGA CLOUD SERVICES, S.L. It carries no date. A Data Processing Addendum at https://taiga.io/data-processing-addendum-dpa/ is incorporated into the terms.",
        "The hosted API answers at api.taiga.io and the web app at tree.taiga.io, both on the vendor's domain. Self-hosted instances answer on the owner's domain.",
        "taiga.io/.well-known/security.txt returned 404. The security page and the repository's SECURITY.md give security@taiga.io for reports.",
        "No status page is linked from the site, the docs or the terms.",
        "RDAP for taiga.io gives a registration date of 2013-12-04 and Gandi SAS as registrar."
      ],
      "score": 72,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Taiga Cloud Services, S.L.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "taiga.io, registered 2013-12-04 (12 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "taiga.io",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 3 clauses that cost points",
          "points": 3.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 6 of the 8 things a reader expects",
          "points": 8.5,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://taiga.io/terms-and-conditions/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2025-09-01",
          "words": 6295,
          "points": 3.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: September 2025",
              "says": "Last updated 2025-09-01"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "These Terms and Conditions shall be governed by the Laws of Spain (both national Spanish laws and all EU applicable laws).",
              "says": "The law of Spain"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "In no event will Taiga's total aggregate liability to you or to any third-party arising out of or in connection to these Terms and Conditions or to your use of (or inability to use) Taiga's Products \u0026 Services exceed the total amount of fees you (or, where applicable, your Customer) actually paid to Taiga during the t…",
              "says": "Capped at the fees paid in the 12 months before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "We have the right, in our sole discretion, to permanently or temporarily suspend your access to and use of Taiga's Products \u0026 Services (including our right to delete your User account), under the following circumstances: (i) for scheduled or emergency maintenance to Taiga's Products \u0026 Services, or any part thereof;"
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "Taiga reserves the right to modify or amend these Terms and Conditions or any of our other policies or guidelines, at any time, upon notice to you.",
              "says": "Says it gives notice of a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "You represent that, when registering a User account, you will provide truthful and up to date information and that you will not use a false identity or the identity of a third party."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.automated",
              "label": "Restricts automated access",
              "found": true,
              "quote": "Among others, the User may not apply \"screen-scraping\" or similar techniques.",
              "costsPoints": true
            },
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "You may not use Taiga's API with the aim of developing a product or a service that is a competitor of Taiga's Products \u0026 Services.",
              "costsPoints": true
            },
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "Taiga reserves the right at any time to modify or discontinue, temporarily or permanently, your access to the Taiga's API (or any part thereof) with or without notice.",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "Taiga reserves the right at any time to modify or discontinue, temporarily or permanently, your access to the Taiga's API (or any part thereof) with or without notice."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Taiga may suspend access or delete an account that has had no login and no project activity for six months.",
              "quote": "(viii) if your User account remains inactive for a continuous period of six (6) months or more, where “inactive” means no login to the account and no activity within any associated project during said period."
            },
            {
              "date": "2026-10-08",
              "text": "API users may not use the API to make data or functions of Taiga's products available to third parties.",
              "quote": "You may not use Taiga's API with the aim of making certain data and functionalities of Taiga's Products \u0026 Services available to third-parties."
            },
            {
              "date": "2026-10-08",
              "text": "Data usage above ten times the median falls outside the fair use policy and Taiga may limit it.",
              "quote": "Fair use policy means not more data usage than 10x of the median. We reserve the right to limit your data usage."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://taiga.io/privacy-policy/",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 2117,
          "points": 8.5,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "We collect information about you when you contact us though the channels provided for this purpose, such as the register form and the payment form."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We will only keep your data for as long as necessary to provide you with these services.",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "The user’s consent, to disclose public projects, to send commercial communications from third parties, always through TAIGA or the installation of tracking systems according to the Cookies Policy."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": false
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "TAIGA is committed to the fundamental right to the protection of your personal data and this privacy policy is intended to inform you of your rights."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "They will be exercised by e-mail: privacy@taiga.io, or at the registered office of TAIGA: Calle Uruguay, 15, Entreplanta B, 36201, Vigo (Pontevedra), Spain.",
              "says": "privacy@taiga.io"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "…securely, either because the provider offers adequate guarantees, through, among others, the signing of Standard Contractual Clauses of the European Commission, or any of the exceptions contained in the regulations.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The policy does not cover personal information Taiga processes as a processor for a customer organisation.",
              "quote": "This policy does not apply to the extent we process personal information in the role of a processor on behalf of your organization."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/taiga.json"
  }
}
