Enterprise Security & Compliance
Jobix.AI protects your data with SOC 2 Type I underway (Type II to follow), end-to-end encryption, GDPR readiness, and responsible AI practices.
Data protection in transit and at rest
All traffic between your systems, the platform and telephony providers runs over TLS 1.2 or higher. Recordings, transcripts and contact records are encrypted at rest with AES-256, and encryption keys are managed and rotated by our cloud provider key service rather than stored in application code.
Access control and tenancy
Every workspace is logically isolated, with role-based access control over agents, campaigns, contact data and recordings. Administrative access to production is limited to a small on-call group, requires SSO with multi-factor authentication, and is logged. SSO and SAML are available for enterprise plans.
Certifications and regulatory posture
SOC 2 Type I is underway with Type II to follow. The platform is built to support GDPR, POPIA and HIPAA obligations, including data subject access and deletion requests, configurable retention windows for recordings and transcripts, and regional data residency options. Payment processing is handled by a PCI-DSS certified provider, so card data never touches our systems.
Monitoring, response and vendors
Production is monitored 24/7 with alerting on availability, latency and error rates, backed by a 99.5% uptime SLA. Security incidents follow a documented response process with customer notification. Every vendor that may process customer data is listed publicly on our subprocessors page and bound by data processing terms at least as strict as our agreement with you.