Trust ยท Security ยท Compliance

Security and compliance you can verify.

The JIFFYAI Trust Center is your single source for our security posture, certifications, and compliance documentation. Browse what's public, or request access to our full report library.

๐Ÿ”’ ISO 27001:2022 Certifiedโœ“ SOC 2 Type II Annual๐Ÿ›ก HIPAA Compliant๐Ÿค– ISO 42001 In Progress๐Ÿ“„ RSA-Signed Downloadsโšก Self-Service NDA Access

Certifications & Attestations

Independently audited and continuously maintained.

GDPR Report 2025

Compliance

GDPR compliance assessment.

Valid through Oct 25, 2026

HIPAA Report 2025

Compliance

HIPAA Compliance Assessment Report

Valid through Oct 25, 2026

ISO 27001 Certificate

Certification

Information security management certification.

Valid through Jun 30, 2027

SOC 1 Type II Report - 2025

Annual Audit

SOC 1 Type II assessment report (Oct 2025 - Oct 2026)

Valid through Oct 25, 2026

SOC 2 Type II Report - 2025

Annual Audit

SOC 2 Type II assessment report (Oct 2025 - Oct 2026)

Valid through Oct 25, 2026

In Progress

ISO 42001

ISO/IEC 42001:2023 โ€” AI Management System

AI management system certification. Audit scheduled August 2026.

AI governance built in, not bolted on.

Every AI inference on the JIFFYAI platform runs through documented governance controls.

Customer data never used to train AI models

Contractually enforced in our DPA (Clause 4.2) and architecturally enforced at the AWS Bedrock API layer. Your data trains nothing.

View DPA

AWS Bedrock Guardrails on 100% of LLM calls

Content moderation, PII filtering, topic blocking, and grounding checks on every inference โ€” independent of application-layer controls.

View AI Usage Policy

Human-in-the-loop for high-risk AI workflows

High-risk AI actions require human confirmation. AI outputs cannot trigger automated downstream actions without approval.

View AI Impact Assessment
In Progress

ISO 42001 AI Management System โ€” audit August 2026

One of very few enterprise AI platforms with a formal ISO 42001 certification programme in progress. Full AIMS documentation in the document library.

View ISO 42001 Readiness Summary

Audit and certification timeline

Where each certification and audit stands, and what's next.

ISO 27001:2022 Active

Last certified: 2024

Valid through Jun 2027

SOC 2 Type II Active

Last certified: Annual Q4

Next: Q4 2026

SOC 1 Type II Active

Last certified: Annual Q4

Next: Q4 2026

HIPAA Active

Last certified: Annual

Annual assessment

GDPR / UK GDPR Active

Last certified: Annual

Annual assessment

ISO 42001 In progress

Last certified: โ€”

Audit: August 2026

CSA STAR Planned

Last certified: โ€”

Q3/Q4 2026

How access works

Three tiers, each with the right level of verification.

1

Public

Available to everyone, no sign-in required โ€” privacy policy and high-level statements.

2

Standard (NDA)

SOC 2, ISO 27001, HIPAA & GDPR reports, security policies, AI governance documentation, and pre-filled security questionnaire. Verify your email, sign our NDA online โ€” instant access.

3

Restricted

Penetration test and internal risk reports. Granted case-by-case by our security team.

Cryptographically verified downloads

Every bulk download includes an RSA-signed manifest with SHA-256 hashes. Verify that documents genuinely originated from trust.jiffy.ai and have not been modified in transit.

Sub-processor list

Public โ€” no NDA required

View the full list of third-party providers that may process customer data โ€” no sign-in required.

View sub-processors

Are you a JIFFYAI employee? Sign in with your Microsoft account from the top navigation for instant full access โ€” no request or NDA required.

Pre-filled security questionnaire โ€” skip the manual DDQ

JIFFYAI has pre-answered 100 security questions across 16 domains: risk management, access control, AI governance, encryption, cloud security, and financial services compliance. Available to all NDA-tier visitors. Export to Excel in one click.

Access Questionnaire

Requires NDA access ยท Sign online in 2 minutes

Infrastructure you can rely on.

Cloud-native on AWS, aligned to ISO 27001:2022, SOC 2 Type II, and HIPAA.

AES-256 Encryption

All data encrypted at rest with AWS KMS Customer Managed Keys. TLS 1.3 minimum for all data in transit.

Zero manual production changes

All infrastructure defined as code (Terragrunt/Terraform). GitOps deployment. AWS Config monitors for drift in real time.

Multi-AZ resilience

Tier 1 services: RTO < 4 hours, RPO < 1 hour. Aurora PostgreSQL Multi-AZ automatic failover. Quarterly DR drills.

MFA everywhere

Multi-factor authentication mandatory for all staff. JumpCloud MDM on all endpoints. HashiCorp Vault for all secrets.

Annual penetration testing

External pen test annually. Scope includes AI/LLM endpoints and all APIs. Findings tracked to closure with defined SLAs.

24/7 monitoring

AWS Security Hub, GuardDuty, CloudTrail, and LangSmith AI monitoring. MTTD < 15 min. MTTR < 25 min.

Stay informed

Get notified when JIFFYAI achieves new certifications, publishes updated reports, or adds documents to the Trust Center.

Notify me about

We'll only email you about Trust Center updates. You can unsubscribe at any time. See our Privacy Policy.

Have a question?

Security enquiries

For questions about our security programme, compliance documentation, or vendor assessments.

Email ciso@jiffy.ai

Schedule a security review

For enterprise customers who need a dedicated security briefing, architecture review, or custom questionnaire.

Request a call