>_Give your agent a brain:https://mcp.jitm.ai·humans, read on ↓
Trust Center

Everything we do with your data, on the record.

No badges we have not earned, no “industry-leading security” hand-waving. Just the actual controls, the actual companies, and the actual retention windows, each one checkable.

100%
of your datasets and models stored in the EU
0 days
AI prompt retention, on every model we use
30 days
to full purge after account deletion
6
subprocessors, total. The list below is complete
Last updated 25 July 2026 · changes announced 30 days ahead
The controls

Not promises. Running code.

Each control below is live in production today. If it says enforced, there is a config or a line of code behind it, and we will show a security reviewer exactly which one.

Your data never trains anyone else's model

Models are trained per account, on your data only. No shared or pooled learning exists in the pipeline.

Enforced

Encryption in transit and at rest

TLS 1.2+ on every connection, AES-256 on every stored file and database.

Enforced

API tokens stored as hashes only

SHA-256, plaintext shown once at creation and never kept. A database leak leaks no working keys.

Enforced

Databases closed to the public internet

Postgres is unreachable from outside, blocked at the firewall. Access runs over a private network.

Enforced

Daily encrypted backups, 30-day window

Nightly to EU object storage. Aged out automatically, so deleted data leaves backups on schedule.

Enforced

Zero-retention AI, always

Agent features only call models configured for zero data retention. A model that cannot guarantee it is excluded.

Enforced

Responsible disclosure

security@jitm.ai · /.well-known/security.txt · answer within 48 hours.

Open

SOC 2 Type II

Not yet, and we will not fake it with a lookalike badge. Planned as the team grows.

Roadmap
Your data's path

Five stops, no detours.

The complete route your CSV takes. If a step is not on this map, it does not happen.

Upload

Leaves your machine encrypted, straight to storage.

TLS 1.2+

Storage · R2

Rests encrypted in EU object storage, scoped to your account.

EU · AES-256

Training · Hetzner

Isolated worker in Germany trains your model. Never pooled.

Germany

Artifacts

Model and evaluation files return to EU storage, owned by you.

EU · AES-256

Predictions

Served from Germany, logged on a 12-month rolling window.

Germany

One disclosed exception: agent features send schema and samples to AI models that may run outside the EU. Full detail in the next section.

AI features · full disclosure

Where AI models are involved,
here is exactly what they see.

JITM's agent features use large language models on Google Vertex AI and Amazon Bedrock to explain your data and your results in plain language. This is the one place data can leave the EU, so it gets the brightest light on the page. Core training never involves an LLM at all.

What we send
  • Column names and data types, so the model can describe your dataset
  • Small samples and summary statistics needed for the specific task
  • Your model's metrics, so results can be explained in plain words
What we never send
  • ×Your raw dataset in bulk. It stays in EU storage
  • ×Anything when you are not using an agent feature
  • ×Your data to any model that stores prompts
Zero data retention. Always.

Neither provider trains on your data, and we only use models and configurations where prompts and outputs are never stored. A model that cannot guarantee this is not used, however capable it is.

Google Vertex AIAmazon Bedrock
Subprocessors

Six companies. The whole list.

ProviderWhat it doesWhereWhat it sees
Hetzner
Compute & databases
Platform, databases, model trainingGermanyAll stored data, encrypted at rest
Cloudflare
Object storage (R2)
Datasets, model artifacts, backups; DNS and traffic securityEUYour files, encrypted at rest; technical traffic data
Clerk
Authentication
Sign-in and accountsUSName and email. Never your datasets
Paddle
Payments
Billing, as merchant of recordUKBilling details. Cards never touch our servers
Google Vertex AI
AI inference
LLMs for agent featuresGlobalSchema and small samples only · zero retention
Amazon Bedrock
AI inference
LLMs for agent featuresGlobalSchema and small samples only · zero retention
Complete list, no seventh company. Changes are announced 30 days ahead. Legally binding version in the Data Processing Agreement →
Retention

Everything expires. Here is when.

DataKept forDelete it sooner
Datasets & trained modelsWhile your account is active · purged ≤ 30 days after deletionDelete any dataset or model from the dashboard
Prediction logs12 months rolling, dropped automaticallyDelete the model, logs go with it
Encrypted backups30 days, aged out automaticallyAutomatic once the live purge runs
AI prompts0 days, never stored by providersNothing to delete
Support conversationsOpen conversation + 12 monthsAsk and it goes
Worked example: delete your account March 1st → live systems clean by March 31st → backups clean by April 30th. After 60 days we could not recover your data if we wanted to.
Compliance

What we have. What we don't. Yet.

GDPR

In place

EU-hosted core, a signable Data Processing Agreement, the complete subprocessor list above, and deletion that actually executes. Export any time; deleted stays deleted.

SOC 2

Roadmap

No SOC 2 report yet. It is planned as the team grows, and until then this page discloses more than most certified vendors do. Security reviewers: email us, we will walk you through any control on this page.

Something this page left out?

Security reviews, DPA requests, disclosure. A human answers, usually the founder.

>_security@jitm.ai