TRUST CENTER
How JibeONE protects your business.
Security architecture, data protection, AI governance, sub-processors, and our compliance posture - in one place.
Four pillars of our security posture
Defense in depth.
Network, application, data, and identity layers each enforce their own controls. A failure at one layer does not compromise the others.
Data isolation.
Tenant data is segregated by deployment. On-premises and private-cloud customers run in their own database, on their own network, behind their own perimeter.
Governed AI.
Jules sees only what the calling user is allowed to see. AI providers do not train on your records.
Auditable everything.
Every save is signed, timestamped, and recorded. Privileged actions are reviewable.
Draft for legal review. Subject to revision. Last updated: 5 July 2026.
The Trust Center is the single place to understand how JibeONE protects your data, who processes it, and where our compliance posture stands. It links to the underlying legal and trust documents.
1. Security architecture: defense in depth
JibeONE is built as four cooperating layers, each of which fails closed — every access decision returns "deny" on missing data, error, or unexpected state:- Network. TLS in transit; the web tier terminates TLS, routes requests, and gates static-asset access.
- Authentication. A single credential store holds bcrypt password hashes keyed by user. Two-factor authentication is mandatory, using either a phishing-resistant WebAuthn passkey or a time-based one-time code, and a deny-by-default session gate means a password alone does not grant data access.
- Authorization. Role-based access control resolves each user's web, entity, and record permissions; there are no admin bypass paths.
- Data. Row-level security is enforced in the database through per-user access predicates, so authorization is applied at the point data is read.
2. Data protection
Data is encrypted in transit. In hosted deployments, data at rest is protected by infrastructure-level encryption; in on-premises and private-cloud deployments, the customer controls the storage layer and its encryption. Sensitive configuration secrets are handled through a protected vault rather than in plain application settings. Access to production is limited and logged.3. Identity and access
Every user authenticates against the single credential store with a mandatory second factor. Administrators manage access through roles and groups; suspending a user's ability to sign in is a single, reversible setting that removes their credential without disturbing their ownership history. Security-relevant actions are recorded to an audit trail.4. Deployment and data residency
JibeONE runs on-premises or in a private cloud. That means the customer chooses where their instance and its data live, and retains control of the environment. This deployment model is central to how JibeONE customers meet their own data-residency and regulatory obligations.5. Availability and resilience
We monitor the production service and operate backup tooling for hosted deployments. Our availability commitment and support targets are described in the Service Level Agreement.6. AI governance
JibeONE's assistant, Jules, works on your records inside your permission model, and we do not train foundation models on your data. The full detail — model provider, tenant isolation, human-in-the-loop posture, and how to disable AI — is on the AI Governance page.7. Sub-processors and compliance
Our current sub-processors and the safeguards we apply are listed on the Sub-processors page. Our honest compliance posture, including SOC 2 progress and regulatory readiness, is on the Compliance page.8. Trust and legal documents
- Privacy Policy
- Terms of Service
- Acceptable Use Policy
- Cookie Notice
- Sub-processors
- Service Level Agreement
- Data Processing Addendum
- Compliance
- AI Governance
- Security & Vulnerability Disclosure