At Jenshinn, we take security seriously. This page outlines our security practices and commitments to protect your data and our platform.
1. Data Protection
- Encryption in transit: All data between your systems and ours is encrypted using TLS 1.2 or higher.
- Encryption at rest: Sensitive data is encrypted at rest using industry-standard encryption.
- Secrets and API keys: API keys and credentials are hashed or encrypted and never stored in plain text.
2. Access Control and Authentication
- Access to production systems and customer data is restricted and based on least privilege.
- We support strong authentication practices; we encourage use of strong passwords and, where available, multi-factor authentication (MFA).
- Access is reviewed regularly and revoked when no longer needed.
3. Infrastructure and Operations
- We use reputable cloud providers and follow security best practices for configuration and hardening.
- We apply patches and updates in a timely manner and monitor for vulnerabilities.
- Logging and monitoring help us detect and respond to suspicious activity.
4. Isolated Runs and Data Handling
Agent runs can be isolated where supported by your plan. We do not use your prompts or data to train third-party models unless you have agreed otherwise. Data handling for AI providers (e.g., OpenAI, Anthropic) is subject to their policies; we recommend reviewing them.
5. Compliance and Audits
We are committed to meeting applicable security and privacy standards. We work toward SOC 2 alignment and follow practices that support compliance with regulations such as GDPR. For enterprise customers, we can provide additional security documentation under NDA.
6. Incident Response
We have procedures to detect, contain, and remediate security incidents. In the event of a breach that affects your data, we will notify you and relevant authorities as required by law.
7. Reporting Security Issues
If you discover a security vulnerability, please report it to us responsibly. Contact us via docs.jenshinn.com or the security contact provided there. We ask that you do not publicly disclose the issue until we have had a chance to address it.