Built for confidentiality and privacy.

    This page describes controls that are implemented in Justera today. It is not a certification, audit report or guarantee that every risk has been eliminated.

    Encrypted in transit and at rest
    TLS + AES-256
    Production data stored in Ireland
    EU/EEA
    Documented technical control areas
    4

    Technical controls

    The descriptions below are deliberately limited to mechanisms that are present in the service.

    Encryption

    Traffic between the browser, application and backend is encrypted with TLS. Databases, uploaded files and backups are encrypted at rest with AES-256 through the infrastructure platform. API keys are stored as one-way SHA-256 hashes where applicable; plaintext is shown only when a key is created.

    Data residency

    Persistent production data is stored in an EU region in Ireland. This statement concerns storage location. Processing required to produce an analysis is governed by the data processing agreement and its sub-processor terms.

    Tenant isolation and access

    Customer data is logically separated by workspace identifiers. Row-Level Security policies in the database enforce workspace membership, while application roles limit which authenticated users can administer, edit or read information. Privileged operations run on the server and validate the signed-in user.

    Analysis and audit records

    Server-side records connect analyses and relevant user actions to a workspace and timestamp. The analysis pipeline also records operational metadata such as model identifier, token usage and processing time. Audit records are not written by the browser, which reduces the risk of client-side alteration.

    Compliance status

    Legal compliance depends on both our controls and how each customer configures and uses the service.

    FrameworkStatusWhat the status means
    GDPRControls implementedTechnical and organisational measures support access control, data minimisation, deletion and processor obligations. This is not an external GDPR certification.
    Norwegian Personal Data ActControls implementedThe service is designed for processing governed by the Act and GDPR. The customer remains responsible for its own lawful basis and use.
    ISO/IEC 27001Not certifiedWe use principles from the standard in internal security work, but Justera does not hold ISO 27001 certification. No certification date has been set.

    Data processing agreement

    We provide a data processing agreement on request. It describes the processing, security measures, deletion terms, transfers and the current sub-processors relevant to the customer. We do not publish a public supplier list because that information belongs in the agreement the customer reviews and signs.

    Send us the organisation name. The request is queued and handled without a stated deadline.

    Request a DPA