Trust center

How Jubi handles your data, in one place.

Last updated: 2026-04-25 · Pre-launch

Every document a security reviewer or procurement team is likely to ask for. If something you need isn't here, email security@jubilabs.ai and we'll send it.

Pre-launch. SOC 2 and ISO 27001 audits are not yet complete. The pages below describe how Jubi operates today and what's on the roadmap. For DPA, SLA, and terms, the signed version controls — not the public copy on this site.

Compliance roadmap

What we have. What we're working on. What's deliberately not in scope. We don't list certifications we don't hold.

In place
PDPA Malaysia · operating posture alignedNotice, consent, purpose limitation, security, and DSR handling are in place. Designated PDPA contact: privacy@jubilabs.ai.
In place
GDPR readinessDPA available with Standard Contractual Clauses and UK addendum where applicable. Sub-processing list, retention schedule, DSR workflow documented.
In place
Provider posture (Anthropic, OpenAI)We use enterprise endpoints configured for no-training and no-retention beyond inference. Posture verified per provider terms current at integration.
Roadmap
Roadmap
In build
Periodic third-party penetration testingApplication surface and Guardian policy enforcement are in scope. A summary will be available under NDA after the next completed test.
Targeted
Targeted
Not in scope
HIPAA, PCI DSS, FedRAMPNot in scope today. Jubi does not target US healthcare, card-holder, or US-federal workflows. We will revisit if and when we do.

Need a security questionnaire filled in?

We respond to CAIQ, SIG-Lite, VPAT/ACR, and customer-supplied formats. Email security@jubilabs.ai with the package and we'll indicate timing on receipt.

Request →