Security
Last updated: July 28, 2026
Questions or concerns? Email security@tryjake.ai. For data handling details, see our privacy policy and terms of service.
Hosting and infrastructure
Jake's primary application infrastructure and customer databases are hosted on Amazon Web Services (AWS) in eu-west-1 (Ireland). Some authorised subprocessors may process limited data outside the EU -- these are listed in the subprocessors table below. Where data is transferred outside the EEA, we rely on the European Commission's standard contractual clauses (SCCs) as the transfer mechanism.
Encryption
Data is encrypted in transit using TLS 1.2 or higher. Data at rest is encrypted using AES-256 via AWS-managed keys.
LLM and AI data handling
Jake supports Bring Your Own Key (BYOK). When you connect an LLM provider using your own API key (OpenAI, Anthropic, Google, or Amazon Bedrock), relevant conversation data is transmitted to that provider to generate a response. The provider's handling of that data is governed by your agreement with them. Jake does not use customer data to train AI models.
All API keys and third-party credentials are encrypted at rest using AWS KMS with per-workspace encryption context, meaning ciphertext is cryptographically bound to your workspace and cannot be decrypted in any other tenant's context.
Customers on eligible managed plans may use Jake-provided model access. Applicable providers and their data handling arrangements are disclosed in our customer agreement. To discuss specific requirements, contact security@tryjake.ai.
Access controls
Access to production infrastructure is restricted to authorised personnel with MFA enforced. We apply the principle of least privilege to AWS IAM roles. Access to customer data is logged.
Backups and recovery
Customer data is backed up daily with a 30-day retention window. Backups are encrypted and stored in the same region as the primary data. On account closure, primary data is deleted within 30 days and backups age out within a further 30 days. You can export your data at any time via self-service.
Security programme
Jake does not currently hold SOC 2 or ISO 27001 certification. We are developing a security programme informed by recognised industry controls and are working toward SOC 2 Type II. Security documentation is available to prospective enterprise customers on request -- email security@tryjake.ai.
Responsible disclosure
If you discover a security vulnerability, please report it to security@tryjake.ai. We ask that you give us reasonable time to investigate and remediate before public disclosure. We do not pursue legal action against researchers who act in good faith.
Subprocessors
Jake uses the following third-party subprocessors to operate the platform. We keep this list current and will notify customers of material changes.
| Company | Purpose | Region |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, databases, storage, KMS encryption, email (SES) | EU (eu-west-1, Ireland) |
| Resend | Transactional email delivery | US |
| PostHog | Product analytics | EU (eu.i.posthog.com) |
| Stripe | Subscription billing | US |
| Context.dev | Web crawling for knowledge source ingestion | US |
| Jina Reader | Fallback web crawling for knowledge source ingestion | US |
LLM providers (OpenAI, Anthropic, Google, Bedrock) are customer-configured via BYOK and not listed above as they are selected and governed by each customer. For questions contact security@tryjake.ai.
