Not promises. Running code.
Each control below is live in production today. If it says enforced, there is a config or a line of code behind it, and we will show a security reviewer exactly which one.
Your data never trains anyone else's model
Models are trained per account, on your data only. No shared or pooled learning exists in the pipeline.
Encryption in transit and at rest
TLS 1.2+ on every connection, AES-256 on every stored file and database.
API tokens stored as hashes only
SHA-256, plaintext shown once at creation and never kept. A database leak leaks no working keys.
Databases closed to the public internet
Postgres is unreachable from outside, blocked at the firewall. Access runs over a private network.
Daily encrypted backups, 30-day window
Nightly to EU object storage. Aged out automatically, so deleted data leaves backups on schedule.
Zero-retention AI, always
Agent features only call models configured for zero data retention. A model that cannot guarantee it is excluded.
Responsible disclosure
security@jitm.ai · /.well-known/security.txt · answer within 48 hours.
SOC 2 Type II
Not yet, and we will not fake it with a lookalike badge. Planned as the team grows.
Five stops, no detours.
The complete route your CSV takes. If a step is not on this map, it does not happen.
Upload
Leaves your machine encrypted, straight to storage.
TLS 1.2+Storage · R2
Rests encrypted in EU object storage, scoped to your account.
EU · AES-256Training · Hetzner
Isolated worker in Germany trains your model. Never pooled.
GermanyArtifacts
Model and evaluation files return to EU storage, owned by you.
EU · AES-256Predictions
Served from Germany, logged on a 12-month rolling window.
GermanyOne disclosed exception: agent features send schema and samples to AI models that may run outside the EU. Full detail in the next section.
Where AI models are involved,
here is exactly what they see.
JITM's agent features use large language models on Google Vertex AI and Amazon Bedrock to explain your data and your results in plain language. This is the one place data can leave the EU, so it gets the brightest light on the page. Core training never involves an LLM at all.
- →Column names and data types, so the model can describe your dataset
- →Small samples and summary statistics needed for the specific task
- →Your model's metrics, so results can be explained in plain words
- ×Your raw dataset in bulk. It stays in EU storage
- ×Anything when you are not using an agent feature
- ×Your data to any model that stores prompts
Neither provider trains on your data, and we only use models and configurations where prompts and outputs are never stored. A model that cannot guarantee this is not used, however capable it is.
Six companies. The whole list.
| Provider | What it does | Where | What it sees |
|---|---|---|---|
| Hetzner Compute & databases | Platform, databases, model training | Germany | All stored data, encrypted at rest |
| Cloudflare Object storage (R2) | Datasets, model artifacts, backups; DNS and traffic security | EU | Your files, encrypted at rest; technical traffic data |
| Clerk Authentication | Sign-in and accounts | US | Name and email. Never your datasets |
| Paddle Payments | Billing, as merchant of record | UK | Billing details. Cards never touch our servers |
| Google Vertex AI AI inference | LLMs for agent features | Global | Schema and small samples only · zero retention |
| Amazon Bedrock AI inference | LLMs for agent features | Global | Schema and small samples only · zero retention |
Everything expires. Here is when.
| Data | Kept for | Delete it sooner |
|---|---|---|
| Datasets & trained models | While your account is active · purged ≤ 30 days after deletion | Delete any dataset or model from the dashboard |
| Prediction logs | 12 months rolling, dropped automatically | Delete the model, logs go with it |
| Encrypted backups | 30 days, aged out automatically | Automatic once the live purge runs |
| AI prompts | 0 days, never stored by providers | Nothing to delete |
| Support conversations | Open conversation + 12 months | Ask and it goes |
What we have. What we don't. Yet.
GDPR
In placeEU-hosted core, a signable Data Processing Agreement, the complete subprocessor list above, and deletion that actually executes. Export any time; deleted stays deleted.
SOC 2
RoadmapNo SOC 2 report yet. It is planned as the team grows, and until then this page discloses more than most certified vendors do. Security reviewers: email us, we will walk you through any control on this page.
Something this page left out?
Security reviews, DPA requests, disclosure. A human answers, usually the founder.