Draft — replace the bracketed items below with your actual practices, tooling, and any real certifications before this page goes live. Do not claim compliance you haven't actually completed.
Security & Trust
Security isn't an afterthought — it's part of how we design and ship every system we build.
Data handling
We collect only the information necessary to deliver our services and respond to inquiries. We do not sell client or visitor data to third parties. See our Privacy Policy for full detail.
Infrastructure
[Describe your actual hosting provider(s), e.g. Vercel/AWS/GCP, and any relevant infrastructure security practices — encryption in transit (TLS), encryption at rest, network isolation, etc.]
Access control
[Describe how access to client systems and data is restricted internally — e.g. least-privilege access, credential rotation, offboarding process.]
Compliance
[State your actual current compliance posture honestly — e.g. "SOC 2 Type II in progress, targeting completion in [quarter/year]" or "available upon request for qualifying engagements." Do not state a certification you do not hold.]
Client confidentiality
We're happy to sign a mutual NDA before any discovery call where sensitive project details are discussed, and standard confidentiality terms are included in every client agreement.
Incident response
[Describe your actual incident response process — who is notified, expected response time, and how affected clients are informed.]
Questions
For security questions or to request documentation for a procurement review, contact support@jupitarai.com.