Security & trust

Built to be audit-ready.

Honest, current-state security posture for Jedah. Updated as we add controls. Last revised June 12, 2026.

Certifications + audits

Where your data lives

Primary: Fly.io US-East (Northern Virginia). Persistent volumes are encrypted at rest. Event log + workspace data stay in this region by default. EU (Frankfurt) and Canada (Montreal) regions on the 2026 H2 roadmap for customers who need data residency.

Encryption

AI handling — your data isn't training models

Interview transcripts, candidate data, and rubric scores get sent to Anthropic's Claude API via the zero-retention enterprise endpoint. That means: Anthropic doesn't store, log, or train on the content of your requests. Your workspace's training corpus — labeled examples you accumulate over time — stays inside your workspace. We never use one customer's data to train scoring for another customer.

Sub-processors

Full list maintained here (notification by email before any addition). Current list:

Authentication + access

Candidate data + GDPR / CCPA / BIPA

Incident response

Security disclosure address: security@jedah.ai. We acknowledge within 24h and remediate critical issues within 7 days. Customers affected by any incident get direct notice within 72h of confirmation.

Pen tests + bug bounty

Annual third-party penetration test on the production app (target: October 2026, post-SOC 2 Type I). Bug bounty program planned for early 2027. Pre-bounty: responsible disclosures get listed in our public security acknowledgments + a swag pack.

Need a security review?

For procurement: email security@jedah.ai with your security questionnaire (Vanta, Whistic, SIG, SIG Lite, CAIQ — all formats accepted). Typical turnaround is 5 business days.