Your data is safe with us
Security isn't a feature we bolt on — it's built into every layer of Jennox, from how we store passwords to how we handle a security incident at 3 AM.
Compliance & Certifications
SOC 2 Type II
In ProgressGDPR Support
AvailableISO 27001
In ProgressData Requests
AvailableRetention Controls
AvailableSSL / TLS 1.3
ActiveSecurity at every layer
From the database to the browser, here's exactly how we keep your data safe.
Encryption at Rest & in Transit
All data stored in MongoDB Atlas is encrypted using AES-256. Every API request and browser session uses TLS 1.3. We never transmit sensitive data over unencrypted channels.
API Key Security
Secret API keys are hashed using SHA-256 before storage — we never store the raw key. Publishable keys are scoped, and all keys support IP whitelisting. One-time reveal on creation.
Authentication & Access Control
JWT-based authentication with short-lived access tokens and secure refresh token rotation. Role-based access control (RBAC) with owner, admin, and member tiers. Audit logs on every sensitive action.
Infrastructure Security
Hosted on Amazon Web Services (AWS) in isolated VPCs. Database access restricted to application servers via IP allowlist. No direct public database access. Automated daily backups with 30-day retention.
Monitoring & Incident Response
Real-time error monitoring via Sentry. Automated anomaly detection for unusual login patterns and API abuse. Dedicated incident response runbook with < 1-hour response SLA for critical security events.
Vulnerability Management
Regular penetration testing by third-party security firms. Automated dependency scanning for known CVEs. Coordinated disclosure program — responsible researchers are credited and rewarded.
Built on world-class infrastructure
AWS + MongoDB Atlas + Cloudfront — redundant, scalable, and secure by design.
AWS EC2
Application servers in isolated VPCs
Monitored availability
MongoDB Atlas
Encrypted database with auto-backups
AES-256 at rest
CloudFront CDN
Global edge network, DDoS protection
< 50ms latency
WAF + Firewall
Web application firewall + IP rules
Layer 7 protection
Common data & security questions
Where is data stored?
Primary data is stored in MongoDB Atlas clusters on AWS in the us-east-1 and eu-west-1 regions. EU customers can request EU-only data residency.
Who has access to my data?
Only authorized Jennox engineers with a documented need. All access is logged, reviewed quarterly, and requires MFA. We never access customer data for advertising or sale.
How long is data retained?
Active account data is retained while your account is active. Deleted accounts are purged within 90 days. Audit logs and billing records are retained 24 months and 7 years respectively, as required by law.
Can I export my data?
Yes. You can export all contacts, conversations, and booking data from your dashboard at any time in JSON or CSV format. No lock-in.
What happens if there's a breach?
We will notify affected customers within 72 hours of discovering a breach, as required by GDPR. We maintain a breach response plan tested annually.
Is your AI trained on my data?
No. Your customer conversation data is never used to train our AI models without explicit consent. AI improvements are based on anonymized, aggregated patterns only.
Responsible Disclosure
Found a security vulnerability? We take all reports seriously. Please disclose responsibly and we'll acknowledge your finding, keep you updated, and credit you publicly (if you wish).
contact@jennox.com · We respond within 24 hours