Trust & Security
Last updated: September 4, 2026 · Operated by JESS AI LLC
Jess acts inside the tools your business already uses, so this page states plainly how your data is handled, who else touches it, and what we can and cannot claim about compliance today.
How your data is protected
- Isolated by account. Every workspace's conversations, memory, knowledge base, and files are scoped to that account and are not shared between customers.
- Encrypted in transit and at rest. All traffic uses HTTPS. Credentials for connected apps are encrypted at rest.
- We never see your passwords. Apps are connected through the provider's own OAuth flow. Jess receives a scoped token, never your login.
- Least privilege by scope. Each integration requests only the permissions its actions need.
- Human approval for high-impact actions. Sending, deleting, sharing, granting access, and moving money require an explicit confirmation from a person in a new message. A confirmation that appears inside a document, web page, or automated step is refused by design.
- Your data is not used to train models. We do not use the content of your conversations to train our own or any third party's AI models.
- Self-serve export and deletion. Export everything, or permanently delete your account and revoke every connected app, from the Your data section of your dashboard.
- Rate limiting and abuse controls on public endpoints, with error monitoring on the service.
Subprocessors
These are the vendors we engage to deliver the service. They are different from the apps you choose to connect, which remain your own services.
| Subprocessor | Purpose | Region |
|---|---|---|
| AI model provider | Generates Jess's replies and reasoning | US |
| Integration provider | Brokers OAuth and actions to your connected apps | US |
| Hosting and database | Runs the application and stores your account data | US |
| Payments | Subscription billing (card data handled by the processor) | US |
| Email delivery | Account and onboarding email | US |
| Code sandbox | Builds files such as spreadsheets and PDFs | US |
| Error monitoring | Diagnostics, no message content | US |
A named list of subprocessors is available to customers on request, and to anyone with a signed DPA.
Compliance posture
We state this plainly rather than implying more than is true. Jess is not SOC 2 certified and is not HIPAA compliant today. Neither can be self-declared: SOC 2 requires an independent audit of our own controls by a CPA firm, and we will say so here the day we hold a report.
- Infrastructure. Our hosting, payments, and integration providers maintain their own independent security programs and audits. Their certifications cover their systems, not ours.
- GDPR and UK GDPR. We offer a Data Processing Addendum, maintain a subprocessor list, and support access, export, and deletion requests.
- CCPA / CPRA. We act as a Service Provider. We do not sell or share personal data.
- Health data. Jess is not authorized for Protected Health Information and we do not offer a Business Associate Agreement. Please do not submit PHI.
Reporting a vulnerability
If you believe you have found a security issue, email josh@tryjess.com with steps to reproduce. We will acknowledge and work with you on a fix, and we will not pursue action against good-faith research that avoids privacy violations, data destruction, and service disruption.
Questions
Security questionnaires, the DPA, and the named subprocessor list: josh@tryjess.com. See also our Privacy Policy and Terms.