The JIFFYAI Trust Center is your single source for our security posture, certifications, and compliance documentation. Browse what's public, or request access to our full report library.
Independently audited and continuously maintained.
GDPR compliance assessment.
Valid through Oct 25, 2026
HIPAA Compliance Assessment Report
Valid through Oct 25, 2026
Information security management certification.
Valid through Jun 30, 2027
SOC 1 Type II assessment report (Oct 2025 - Oct 2026)
Valid through Oct 25, 2026
SOC 2 Type II assessment report (Oct 2025 - Oct 2026)
Valid through Oct 25, 2026
ISO/IEC 42001:2023 โ AI Management System
AI management system certification. Audit scheduled August 2026.
Every AI inference on the JIFFYAI platform runs through documented governance controls.
Contractually enforced in our DPA (Clause 4.2) and architecturally enforced at the AWS Bedrock API layer. Your data trains nothing.
View DPAContent moderation, PII filtering, topic blocking, and grounding checks on every inference โ independent of application-layer controls.
View AI Usage PolicyHigh-risk AI actions require human confirmation. AI outputs cannot trigger automated downstream actions without approval.
View AI Impact AssessmentOne of very few enterprise AI platforms with a formal ISO 42001 certification programme in progress. Full AIMS documentation in the document library.
View ISO 42001 Readiness SummaryWhere each certification and audit stands, and what's next.
| Certification | Status | Last certified | Next audit / expiry |
|---|---|---|---|
| ISO 27001:2022 | Active | 2024 | Valid through Jun 2027 |
| SOC 2 Type II | Active | Annual Q4 | Next: Q4 2026 |
| SOC 1 Type II | Active | Annual Q4 | Next: Q4 2026 |
| HIPAA | Active | Annual | Annual assessment |
| GDPR / UK GDPR | Active | Annual | Annual assessment |
| ISO 42001 | In progress | โ | Audit: August 2026 |
| CSA STAR | Planned | โ | Q3/Q4 2026 |
Last certified: 2024
Valid through Jun 2027
Last certified: Annual Q4
Next: Q4 2026
Last certified: Annual Q4
Next: Q4 2026
Last certified: Annual
Annual assessment
Last certified: Annual
Annual assessment
Last certified: โ
Audit: August 2026
Last certified: โ
Q3/Q4 2026
Three tiers, each with the right level of verification.
Available to everyone, no sign-in required โ privacy policy and high-level statements.
SOC 2, ISO 27001, HIPAA & GDPR reports, security policies, AI governance documentation, and pre-filled security questionnaire. Verify your email, sign our NDA online โ instant access.
Penetration test and internal risk reports. Granted case-by-case by our security team.
Every bulk download includes an RSA-signed manifest with SHA-256 hashes. Verify that documents genuinely originated from trust.jiffy.ai and have not been modified in transit.
View the full list of third-party providers that may process customer data โ no sign-in required.
Are you a JIFFYAI employee? Sign in with your Microsoft account from the top navigation for instant full access โ no request or NDA required.
JIFFYAI has pre-answered 100 security questions across 16 domains: risk management, access control, AI governance, encryption, cloud security, and financial services compliance. Available to all NDA-tier visitors. Export to Excel in one click.
Access QuestionnaireRequires NDA access ยท Sign online in 2 minutes
Cloud-native on AWS, aligned to ISO 27001:2022, SOC 2 Type II, and HIPAA.
All data encrypted at rest with AWS KMS Customer Managed Keys. TLS 1.3 minimum for all data in transit.
All infrastructure defined as code (Terragrunt/Terraform). GitOps deployment. AWS Config monitors for drift in real time.
Tier 1 services: RTO < 4 hours, RPO < 1 hour. Aurora PostgreSQL Multi-AZ automatic failover. Quarterly DR drills.
Multi-factor authentication mandatory for all staff. JumpCloud MDM on all endpoints. HashiCorp Vault for all secrets.
External pen test annually. Scope includes AI/LLM endpoints and all APIs. Findings tracked to closure with defined SLAs.
AWS Security Hub, GuardDuty, CloudTrail, and LangSmith AI monitoring. MTTD < 15 min. MTTR < 25 min.
Get notified when JIFFYAI achieves new certifications, publishes updated reports, or adds documents to the Trust Center.
For questions about our security programme, compliance documentation, or vendor assessments.
Email ciso@jiffy.aiFor enterprise customers who need a dedicated security briefing, architecture review, or custom questionnaire.
Request a call