Jents ← Back to jents.io

Jents

Security & Trust

Last updated 2026-08-11 · security@jents.io · Download PDF

Jents is the governance, cost, and control layer for an organization's AI agents. Because that job means handling sensitive operational data, security and tenant isolation are designed into our foundation, not bolted on. This document explains how we protect your data. We're an early-stage company building toward formal certification (see Compliance), and we're glad to complete your security questionnaire, sign an NDA/DPA, and walk your team through any of this.

1.Tenant isolation — your data is never visible to another customer

This is our most important guarantee, enforced at three independent layers:

We verify this automatically. Our continuous-integration pipeline includes (a) a build-blocking guardrail that fails any change introducing a query that isn't company-scoped, and (b) automated cross-tenant tests that assert one company cannot read, update, or delete another's records. Isolation cannot silently regress between releases.

2.Your API keys and secrets

3.What data we process and store

By default, Jents stores only metadata about your AI calls — not the content of your prompts or responses. We practice strict data minimization:

Connected data sources (ROI measurement). To measure the business impact of your agents, you may connect systems such as your CRM, support desk, data warehouse, product analytics, billing, or project tools — always read-only and scoped to only the metrics you choose. Jents reads these in two ways, and in neither does it read the body of a record.

We do not sell your data, and we do not use it to train models.

4.Encryption

5.Authentication & access control

6.Infrastructure & subprocessors

Jents is built on established, SOC 2-certified infrastructure. Current subprocessors:

Provider Purpose
Vercel Application hosting (SOC 2 Type II)
Supabase Primary database — PostgreSQL, encrypted at rest (SOC 2)
WorkOS Authentication / SSO / directory (SOC 2 Type II)
Railway Metering gateway hosting
Sentry Error monitoring / diagnostics — secrets stripped before send
PostHog Product analytics (US) — identifies users by work email
Stripe Payment processing (PCI DSS Level 1)
OpenAI / Anthropic / Google LLM inference — via your BYOK keys
AWS / Google Cloud / Microsoft Azure Model inference and agent inventory — only if you connect your own cloud account
Slack / email Alert delivery — only if you connect it

Data residency: Jents' application data is hosted in the AWS US East (N. Virginia) region (via Supabase). If your organization requires data to remain in a specific region (e.g. EU), we can discuss this for enterprise engagements. A current subprocessor list is available on request, and we give notice of material changes.

7.How a call flows (data path)

  1. Your agent calls the Jents gateway using a per-agent key you provision.
  2. The gateway forwards the request to your chosen vendor using your own (BYOK) key.
  3. The gateway records cost + token usage (never your secret keys) and sends that metering data to Jents, attributed to the right agent and company.
  4. You see cost, attribution, budgets, and alerts in the Jents dashboard — scoped to your company only.

8.Availability, backups & data ownership

9.Compliance posture (honest, early-stage)

10.Secure development & monitoring

11.Deployment options

12.Reporting a vulnerability / contact

We welcome responsible disclosure. Please email security@jents.io with any security concern; we'll acknowledge promptly and keep you updated. For questionnaires, a DPA, or a walkthrough with your security team, reach out to the same address.

This overview describes Jents' security posture as of the date above and is provided for evaluation. It is not a contractual commitment except where incorporated into a signed agreement. © Jents.