Jake

Security

Last updated: July 28, 2026

Questions or concerns? Email security@tryjake.ai. For data handling details, see our privacy policy and terms of service.

Hosting and infrastructure

Jake's primary application infrastructure and customer databases are hosted on Amazon Web Services (AWS) in eu-west-1 (Ireland). Some authorised subprocessors may process limited data outside the EU -- these are listed in the subprocessors table below. Where data is transferred outside the EEA, we rely on the European Commission's standard contractual clauses (SCCs) as the transfer mechanism.

Encryption

Data is encrypted in transit using TLS 1.2 or higher. Data at rest is encrypted using AES-256 via AWS-managed keys.

LLM and AI data handling

Jake supports Bring Your Own Key (BYOK). When you connect an LLM provider using your own API key (OpenAI, Anthropic, Google, or Amazon Bedrock), relevant conversation data is transmitted to that provider to generate a response. The provider's handling of that data is governed by your agreement with them. Jake does not use customer data to train AI models.

All API keys and third-party credentials are encrypted at rest using AWS KMS with per-workspace encryption context, meaning ciphertext is cryptographically bound to your workspace and cannot be decrypted in any other tenant's context.

Customers on eligible managed plans may use Jake-provided model access. Applicable providers and their data handling arrangements are disclosed in our customer agreement. To discuss specific requirements, contact security@tryjake.ai.

Access controls

Access to production infrastructure is restricted to authorised personnel with MFA enforced. We apply the principle of least privilege to AWS IAM roles. Access to customer data is logged.

Backups and recovery

Customer data is backed up daily with a 30-day retention window. Backups are encrypted and stored in the same region as the primary data. On account closure, primary data is deleted within 30 days and backups age out within a further 30 days. You can export your data at any time via self-service.

Security programme

Jake does not currently hold SOC 2 or ISO 27001 certification. We are developing a security programme informed by recognised industry controls and are working toward SOC 2 Type II. Security documentation is available to prospective enterprise customers on request -- email security@tryjake.ai.

Responsible disclosure

If you discover a security vulnerability, please report it to security@tryjake.ai. We ask that you give us reasonable time to investigate and remediate before public disclosure. We do not pursue legal action against researchers who act in good faith.

Subprocessors

Jake uses the following third-party subprocessors to operate the platform. We keep this list current and will notify customers of material changes.

CompanyPurposeRegion
Amazon Web Services (AWS)Cloud hosting, databases, storage, KMS encryption, email (SES)EU (eu-west-1, Ireland)
ResendTransactional email deliveryUS
PostHogProduct analyticsEU (eu.i.posthog.com)
StripeSubscription billingUS
Context.devWeb crawling for knowledge source ingestionUS
Jina ReaderFallback web crawling for knowledge source ingestionUS

LLM providers (OpenAI, Anthropic, Google, Bedrock) are customer-configured via BYOK and not listed above as they are selected and governed by each customer. For questions contact security@tryjake.ai.

Security | Jake