Security & Trust

Your data is safe with us

Security isn't a feature we bolt on — it's built into every layer of Jennox, from how we store passwords to how we handle a security incident at 3 AM.

Compliance & Certifications

SOC 2 Type II

In Progress

GDPR Support

Available

ISO 27001

In Progress

Data Requests

Available

Retention Controls

Available

SSL / TLS 1.3

Active
How We Protect You

Security at every layer

From the database to the browser, here's exactly how we keep your data safe.

Encryption at Rest & in Transit

All data stored in MongoDB Atlas is encrypted using AES-256. Every API request and browser session uses TLS 1.3. We never transmit sensitive data over unencrypted channels.

API Key Security

Secret API keys are hashed using SHA-256 before storage — we never store the raw key. Publishable keys are scoped, and all keys support IP whitelisting. One-time reveal on creation.

Authentication & Access Control

JWT-based authentication with short-lived access tokens and secure refresh token rotation. Role-based access control (RBAC) with owner, admin, and member tiers. Audit logs on every sensitive action.

Infrastructure Security

Hosted on Amazon Web Services (AWS) in isolated VPCs. Database access restricted to application servers via IP allowlist. No direct public database access. Automated daily backups with 30-day retention.

Monitoring & Incident Response

Real-time error monitoring via Sentry. Automated anomaly detection for unusual login patterns and API abuse. Dedicated incident response runbook with < 1-hour response SLA for critical security events.

Vulnerability Management

Regular penetration testing by third-party security firms. Automated dependency scanning for known CVEs. Coordinated disclosure program — responsible researchers are credited and rewarded.

Infrastructure

Built on world-class infrastructure

AWS + MongoDB Atlas + Cloudfront — redundant, scalable, and secure by design.

AWS EC2

Application servers in isolated VPCs

Monitored availability

MongoDB Atlas

Encrypted database with auto-backups

AES-256 at rest

CloudFront CDN

Global edge network, DDoS protection

< 50ms latency

WAF + Firewall

Web application firewall + IP rules

Layer 7 protection

Your Data

Common data & security questions

Where is data stored?

Primary data is stored in MongoDB Atlas clusters on AWS in the us-east-1 and eu-west-1 regions. EU customers can request EU-only data residency.

Who has access to my data?

Only authorized Jennox engineers with a documented need. All access is logged, reviewed quarterly, and requires MFA. We never access customer data for advertising or sale.

How long is data retained?

Active account data is retained while your account is active. Deleted accounts are purged within 90 days. Audit logs and billing records are retained 24 months and 7 years respectively, as required by law.

Can I export my data?

Yes. You can export all contacts, conversations, and booking data from your dashboard at any time in JSON or CSV format. No lock-in.

What happens if there's a breach?

We will notify affected customers within 72 hours of discovering a breach, as required by GDPR. We maintain a breach response plan tested annually.

Is your AI trained on my data?

No. Your customer conversation data is never used to train our AI models without explicit consent. AI improvements are based on anonymized, aggregated patterns only.

Responsible Disclosure

Found a security vulnerability? We take all reports seriously. Please disclose responsibly and we'll acknowledge your finding, keep you updated, and credit you publicly (if you wish).

contact@jennox.com · We respond within 24 hours