Certifications + audits
- SOC 2 Type I — audit in progress with Drata. Target completion Q3 2026. Letter of engagement available on request for procurement.
- SOC 2 Type II — planned for Q4 2026 / Q1 2027 (requires 6 months of Type I observation).
- ISO 27001 — on the roadmap, post-SOC 2.
- HIPAA — not in scope today. BAAs available on Enterprise tier if you have a specific use case.
Where your data lives
Primary: Fly.io US-East (Northern Virginia). Persistent volumes are encrypted at rest. Event log + workspace data stay in this region by default. EU (Frankfurt) and Canada (Montreal) regions on the 2026 H2 roadmap for customers who need data residency.
Encryption
- In transit: TLS 1.3 everywhere. HSTS enforced. No HTTP fallback.
- At rest: AES-256 on Fly persistent volumes. Database encrypted via Fly Postgres default.
- Backups: nightly to S3 with separate access keys. 30-day retention.
AI handling — your data isn't training models
Interview transcripts, candidate data, and rubric scores get sent to Anthropic's Claude API via the zero-retention enterprise endpoint. That means: Anthropic doesn't store, log, or train on the content of your requests. Your workspace's training corpus — labeled examples you accumulate over time — stays inside your workspace. We never use one customer's data to train scoring for another customer.
Sub-processors
Full list maintained here (notification by email before any addition). Current list:
- Anthropic — AI inference (scoring, analysis, deep reads)
- Fly.io — application hosting + persistent storage
- Netlify — marketing site hosting (this page)
- Bright Data — LinkedIn profile data (licensed)
- Stripe — payments
- Resend — transactional email
- Slack — optional integration (your workspace's app token only)
- Google — optional Calendar integration (OAuth scope: calendar.events)
Authentication + access
- SSO: Google OAuth out of the box. SAML SSO available on Enterprise tier.
- SCIM: provisioning + deprovisioning on Enterprise.
- Session management: HTTP-only, secure, SameSite cookies. 30-day default expiry.
- Password hashing: Node scrypt with per-user salt. No native dependencies — no LD_LIBRARY_PATH surprises.
- Audit logs: on Enterprise — every workspace event with actor + timestamp, exportable to your SIEM via webhook.
Candidate data + GDPR / CCPA / BIPA
- Lawful basis: legitimate interest for recruiting (GDPR Art. 6(1)(f)).
- Candidate rights: data subject access requests honored within 30 days; right to deletion supported.
- Consent disclosures: jurisdiction-aware — BIPA notice for Illinois, NYC LL144 bias-audit disclosure for New York City, CCPA notice for California.
- Bias audits: NYC LL144 annual bias audit reporting on the Enterprise roadmap. Reach out if your jurisdiction requires it sooner.
- EU AI Act compliance: planned, not yet available. Currently serving US/Canada only for AI-graded interview scoring.
Incident response
Security disclosure address: security@jedah.ai. We acknowledge within 24h and remediate critical issues within 7 days. Customers affected by any incident get direct notice within 72h of confirmation.
Pen tests + bug bounty
Annual third-party penetration test on the production app (target: October 2026, post-SOC 2 Type I). Bug bounty program planned for early 2027. Pre-bounty: responsible disclosures get listed in our public security acknowledgments + a swag pack.
Need a security review?
For procurement: email security@jedah.ai with your security questionnaire (Vanta, Whistic, SIG, SIG Lite, CAIQ — all formats accepted). Typical turnaround is 5 business days.