Security & Policies
Last updated: September 9, 2026
This page describes Jevy AI's security controls, data handling practices, and incident response procedures.
Scope of Data Processing
Jevy processes the minimum data required to verify customer outcomes. Data categories are fixed per engagement and documented in writing before any transfer occurs.
| Data category | Purpose | Classification | Retained |
|---|---|---|---|
| Customer name | Survey personalization and routing | Personal data | Duration of engagement |
| Customer email address | Survey delivery | Personal data | Duration of engagement |
| Support conversation content | Grounding verification in the actual interaction | Client confidential | Duration of engagement |
| Interaction metadata (timestamps, channel, agent type, disposition) | Attribution and segmentation | Client confidential | Duration of engagement |
| Survey responses | Verification output | Client confidential | Duration of engagement |
Jevy does not request or process payment card data, government identifiers, health information, or credentials.
Data Transfer and Ingestion
- Transfers occur over TLS 1.2 or higher. Plaintext transfer channels, including email attachment and unencrypted file transfer, are not accepted.
- Data should be transferred through channels authenticated with tokens or one-time secure file transfer for bounded pilot datasets.
- Integration credentials are scoped to read-only, least-privilege access and are revocable by the client at any time without Jevy's involvement.
- Pilot engagements default to a bounded one-time export with a defined date range rather than standing system access.
Infrastructure and Network Security
- All production infrastructure is hosted in North America. No client data is stored on employee endpoints.
- Infrastructure is defined and deployed as code. All changes are version-controlled, peer-reviewed before merge, and applied through an automated pipeline. Manual console changes to production are not permitted, which gives a complete auditable history of every configuration change and its author.
- Public traffic services use WAF, DDoS mitigation, bot management, and TLS termination at the edge. Origin infrastructure is not directly reachable from the public internet.
- Production environments are network-isolated from development and staging. Client data is never copied into non-production environments; testing uses synthetic or anonymized datasets.
- Client data is logically isolated per tenant, enforced at the database or virtual machine layer.
- Audit logging is enabled across all accounts, with logs written to a tamper-resistant store.
Encryption
- All data is encrypted at rest using AES-256 or better. Encryption is enforced at the storage layer and cannot be disabled per-resource.
- In transit: TLS 1.2 or higher for all external traffic and all service-to-service communication carrying client data.
Identity and Access Management
- Access to client data is granted on a least-privilege, need-to-know basis and is tied to a named individual. Shared or generic accounts are not used.
- Employee credentials are managed through a password manager.
- Multi-factor authentication is enabled for all accounts, and enforced where possible. Credentials that cannot be individually provisioned are stored in access-controlled vaults with per-user audit trails rather than distributed directly.
- Single sign-on with mandatory multi-factor authentication is centrally administered.
- Access is provisioned at onboarding against a defined role, reviewed on a quarterly cadence, and revoked within 4 hours of role change or termination.
- Production database access is time-bound and requires documented justification.
- All access to client data is logged, including identity, timestamp, and records accessed. Logs are retained for 12 months and are tamper-evident.
AI and Model Data Handling
Jevy uses large language models to deliver its services. This section states how client data interacts with those models.
- Client data is not used to train, fine-tune, or improve any third-party foundation model. Jevy's agreements with any third party model provider will always stipulate no data may be used in training, fine-tuning, or improving models.
- Jevy uses LLM providers with a documented Zero Data Retention (ZDR) agreement for all client data processing.
- Client data is not used to train Jevy's own models across tenants. Any model tuning is performed within a single tenant's boundary or on synthetic data.
Application Security
- All code changes require peer review and approval by automated test and review systems before merge. Direct commits to production branches are blocked.
- Automated dependency scanning runs on every build. Critical and high severity findings block deployment.
- Secrets are securely managed for infrastructure and are never committed to source control. Automated secret scanning runs on all commits.
- Application logs are scrubbed of personal data and message content at source, within the application logging layer, before transmission to monitoring systems.
- Third-party penetration testing is conducted annually. Summary reports are available to clients under NDA.
- Vulnerabilities can be disclosed to security@getjevy.com.
Incident Response
Jevy maintains a documented incident response plan covering detection, containment, notification, eradication, recovery, and post-incident review. The plan is reviewed annually and after any Severity 1 or 2 incident.
Severity classification
| Severity | Definition | Target initial response |
|---|---|---|
| SEV-1 | Confirmed unauthorized access to, disclosure of, or loss of client data | Immediate escalation and prioritized containment upon awareness. |
| SEV-2 | Suspected unauthorized access, or a vulnerability with a credible path to client data | Urgent escalation and investigation upon awareness. |
| SEV-3 | Security-relevant defect or control failure with no evidence of data exposure | 1 business day |
| SEV-4 | Low-risk finding, policy deviation, or informational report | 5 business days |
Response phases
1) Detect and declare. Any suspected client data exposure is declared SEV-1 or SEV-2 immediately; severity is downgraded only after investigation, never assumed downward at declaration.
2) Assign command. An Incident Commander is designated at declaration and owns the response end to end. A separate communications owner is assigned for any incident involving client notification, so that investigation and communication do not compete for the same person's attention.
3) Contain. Immediate actions include credential revocation, session termination, network isolation of affected components, and suspension of the affected integration. Containment takes priority over evidence preservation only where exposure is ongoing.
4) Preserve and investigate. Logs, snapshots, and system state relevant to the incident are preserved before remediation alters them. Investigation establishes scope: which tenants, which data categories, which records, over what window.
5) Notify. Affected clients are notified without undue delay and no later than 24 hours after Jevy confirms unauthorized access to or disclosure of their data. Notification includes what is known, what is not yet known, containment actions taken, and the next update time. Jevy does not delay initial notification pending a complete investigation. Where Jevy acts as a processor under GDPR, notification supports the client's own 72-hour regulatory obligation.
6) Eradicate and recover. Root cause is remediated, affected credentials and keys rotated, and service restored only after validation that the vector is closed.
7) Post-incident review. A written review is completed within 10 business days of resolution for all SEV-1 and SEV-2 incidents, covering timeline, root cause, contributing factors, and corrective actions with named owners and due dates. A summary is available to affected clients on request.
Data Retention and Deletion
- Client data is retained only for the duration of the engagement and the purpose defined in the applicable agreement.
- On termination or written request, client data is deleted from production systems within 30 days.
- A written certificate of deletion is provided on request.
- Deletion requests directed at individual data subjects are actioned within 30 days.
- Jevy retains no client data for its own commercial use, benchmarking, or product development following termination.
Business Continuity
- Automated encrypted backups run daily with restoration tested quarterly.
- Infrastructure is deployed across multiple cloud hosting availability zones within the hosting region.
Personnel Security
- All employees and contractors execute confidentiality agreements as a condition of engagement.
- Security awareness training is completed at onboarding and annually thereafter.
- Access is revoked as part of a documented offboarding checklist executed on the final day of engagement.
Compliance Posture
| Framework | Status | Detail |
|---|---|---|
| SOC 2 Type II | Uncertified | Controls in this document are implemented and designed against the Trust Services Criteria. Formal audit will be initiated ahead of general availability. |
| GDPR | Compliant by design | Data minimization, purpose limitation, deletion on request, and data subject request support. |
| CCPA/CPRA | Supported | Jevy acts as a service provider and does not sell or share personal information. |
Jevy does not hold SOC 2 certification. Company controls and processes are designed to meet SOC 2 Type II standards, in anticipation of the upcoming audit process.
Jevy manages data in compliance with GDPR, including data minimization, deletion on request, purpose limitation, and data subject request support. For GDPR related requests, contact Jevy's DPO.
Subprocessors
Jevy publishes the third parties that process client data on its behalf, along with the function each performs and the data categories each one handles. Clients receive 30 days' advance notice of any new subprocessor with the right to object.
Contact
Security inquiries and vulnerability reports: security@getjevy.com
Data protection and privacy: Benji Visser, DPO, benji@getjevy.com