Juniper OS runs your business, so it has to be trustworthy by construction. This page is the honest summary of how we protect your data and where our compliance stands — no badges we haven't earned.
Security
- Tenant isolation at the database. Every table enforces Postgres Row-Level Security — application code cannot read across customers.
- Encryption. AES-256 at rest, TLS 1.3 in transit. Integration credentials are encrypted with a separate key.
- Authentication. Email verification, optional TOTP multi-factor auth, per-device session management, and breached-password checks.
- Authority rails. The AI acts only within the tier you choose, and 11 non-overridable rails (spend limits, deletions, legal, regulatory, public posts, …) always require your approval.
- Immutable audit trail. Agent actions and consent decisions are written to append-only logs that even a compromised key can't rewrite.
Data & privacy
- UK residency. Your data lives in Supabase (Postgres) in the eu-west-2 (London) region.
- UK GDPR aligned. Self-serve data export and deletion (with a recovery window), an immutable consent ledger, and a 72-hour breach-notification commitment.
- See our sub-processors, Data Processing Agreement, retention schedule and privacy notice.
Compliance status
- UK GDPR: aligned today (export, deletion, consent ledger, residency, DPA available on request).
- SOC 2: in progress — the platform controls (access control, encryption, change management, monitoring) are in place; the formal Type I → II audit is on the roadmap. We'll publish the report here when complete.
- Cyber Essentials / ISO 27001: under consideration for UK SMB assurance.
Reliability & incidents
The platform has a one-button pause that halts all automated action during an incident, and server errors flow to a central monitoring stream. Planned and notable changes are published on our changelog.
Report a security issue
Found something? Please email security@juniperenterprises.co.uk — we read these first.