Security & Trust
You handle clients’ financial lives, and your license is on the line for how their information is treated. So is ours. Here’s exactly how Jordyn protects your data — in plain terms, including what we are and aren’t.
Your data is walled off — at the database, not just the app
Every record in Jordyn is fenced to your account by row-level security enforced inside the database itself (Supabase Postgres) — not merely by application code that could have a bug. Nearly 250 access rules govern who can read what, and one account’s data is unreachable by another’s login by construction.
When you deliberately share something — a pipeline, a contact list, a document — it goes only to the exact person and permission you grant, and you can revoke it in one click. Nothing is shared by default.
We never hold your passwords or keys
When you connect Gmail, Outlook, a calendar, Dropbox, or any of 250+ apps, the sign-in is brokered securely — Jordyn is authorized to act on your behalf, but we never see or store your passwords or OAuth tokens. We hold no keys to your accounts, so there are no keys to leak. Disconnect any app at any time and that access ends immediately.
Any credential or key that ever appears in text is automatically redacted before it is logged or shown — you may have seen “[key redacted for your security]” in chat; that’s this protection working.
Encrypted, and not sitting anywhere it shouldn't
All traffic is encrypted in transit (HTTPS), and the app runs on Vercel’s SOC 2-compliant infrastructure. Requests are handled and returned — Jordyn doesn’t keep copies of your data on servers that outlive the work you asked for.
Your conversations aren't training data, and we don't sell anything
Jordyn’s AI runs on Anthropic’s Claude under their business data terms: your conversations and documents are not used to train AI models. And we never sell your data, or your clients’ data, to anyone. It is used to do the work you ask for — nothing else.
Your email and calls stay yours
Some things can never be shared out of an account, no matter what — your inbox, your chat history, your phone and voice sessions, and your billing. Jordyn reads your email to help you draft and file, but there is no path to hand your mailbox, your calls, or your card to another account. Those are yours alone.
What we are — and what we're not
Being straight about the limits is part of being trustworthy:
- We build on SOC 2-certified infrastructure (Supabase, Vercel). Jordyn’s own SOC 2 certification is in progress — we’ll say so here the day it’s complete, not before.
- Jordyn is not a HIPAA-covered entity — please don’t upload protected health information.
- You own your data. Request an export or deletion at any time and we’ll honor it.
