← Back to Jess

Trust & Security

Last updated: September 4, 2026 · Operated by JESS AI LLC

Jess acts inside the tools your business already uses, so this page states plainly how your data is handled, who else touches it, and what we can and cannot claim about compliance today.

How your data is protected

Subprocessors

These are the vendors we engage to deliver the service. They are different from the apps you choose to connect, which remain your own services.

SubprocessorPurposeRegion
AI model providerGenerates Jess's replies and reasoningUS
Integration providerBrokers OAuth and actions to your connected appsUS
Hosting and databaseRuns the application and stores your account dataUS
PaymentsSubscription billing (card data handled by the processor)US
Email deliveryAccount and onboarding emailUS
Code sandboxBuilds files such as spreadsheets and PDFsUS
Error monitoringDiagnostics, no message contentUS

A named list of subprocessors is available to customers on request, and to anyone with a signed DPA.

Compliance posture

We state this plainly rather than implying more than is true. Jess is not SOC 2 certified and is not HIPAA compliant today. Neither can be self-declared: SOC 2 requires an independent audit of our own controls by a CPA firm, and we will say so here the day we hold a report.

Reporting a vulnerability

If you believe you have found a security issue, email josh@tryjess.com with steps to reproduce. We will acknowledge and work with you on a fix, and we will not pursue action against good-faith research that avoids privacy violations, data destruction, and service disruption.

Questions

Security questionnaires, the DPA, and the named subprocessor list: josh@tryjess.com. See also our Privacy Policy and Terms.