Security & trust
Your organization's data — the documents you upload, the conversations you have with Ellie, the workflows and frameworks you build — is often among the most sensitive information your team handles. We treat it that way. This page sets out, in plain language, exactly how JobKred protects it, what we do, and what we don't. We'd rather tell you precisely where we stand than gloss over it.
If your security or compliance team is running a formal vendor review, we welcome it — reach out to your JobKred representative for our detailed security documentation, prepared for exactly that purpose.
Your data is yours — full stop
Everything you upload or create in JobKred belongs to your organization. We process it for one reason only: to deliver the service you're paying for. We don't sell it, we don't mine it, and we don't repurpose it.
We never use your data to train AI models. JobKred does no model training of its own, and our AI provider is contractually barred, under its commercial API terms, from using data sent through the API to train its models. Your documents and conversations make your answers sharper — and nobody else's.
We also ask the AI provider not to keep a copy. Every request we send — whether it comes from a chat, a workflow, or anywhere else in the product — carries an instruction telling the provider not to retain the prompt or the answer on its side. It's enforced in our code and checked automatically on every change.
Where your data lives
JobKred's platform — the application, the databases, and your file storage — runs in Singapore, on Amazon Web Services, one of the most rigorously certified cloud infrastructures in the world.
To deliver AI features, some processing involves trusted, industry-standard service providers outside Singapore: your AI requests are processed by our AI provider in the United States, payments are handled by Stripe, and we use established monitoring tools to keep the service reliable and secure. We keep this list deliberately short, and your security team can request the full inventory of providers and exactly what each one handles.
Encryption, everywhere it counts
Your data is encrypted in transit — every connection between your browser and JobKred, and between JobKred and its service providers, is protected with TLS. Your data is encrypted at rest in our storage systems, and the most sensitive items of all — such as the credentials for any integrations you connect — carry an additional, dedicated layer of application-level encryption on top.
Your organization is walled off from every other
JobKred is multi-tenant, and isolation isn't an afterthought — it's checked on every single request against your organization's own membership records before any data is returned:
- People see only what belongs to their organization. Sharing works strictly between colleagues in the same organization — it can never reach into another company, and another company can never reach into yours.
- When Ellie searches your documents to answer a question, it can only ever retrieve content from the files and conversations you already have access to. There is no path by which one organization's content could surface in another's results.
- Roles — User and Admin — govern what each person can do, and administrators see activity only for their own organization.
Accounts, sessions, and a clear record of who did what
- Passwords are protected with industry-standard hashing, and sign-in is defended against automated guessing.
- The moment an administrator removes someone, or a password changes, existing sessions are signed out immediately, across every device — no lingering access.
- Administrative and account activity is captured in an append-style audit trail — who did what, when, and from where — giving your organization an accountable, reviewable record.
Card details are collected and stored by Stripe, our payment processor — a PCI DSS Level 1 provider. They never reach JobKred's servers. See the Billing & payments FAQ.
How Ellie uses AI — with you in control
Ellie is powered by leading commercial AI models, accessed as a service: the content you submit is sent to the AI provider to generate an answer, and the results are stored in your workspace as content you own, like anything else you create.
- Built-in guardrails resist attempts to manipulate the AI with malicious instructions, and organizations can switch on additional content policies to match their standards.
- Humans stay in the loop. Workflows can pause and wait for a person's decision before continuing, so nobody is handed a consequential outcome without the chance to review it.
- Nothing is hidden. AI-generated results are clearly presented in your chats and reports, and the cost of each action is visible as you go.
Our compliance posture — stated plainly
We hold ourselves to the same honesty we'd want from any vendor:
- ISO 27001 certification is on our roadmap. We do not yet hold ISO 27001, SOC 2, or other security certifications — and we will not claim them until we've earned them.
- JobKred is a Singapore company and builds to the principles of Singapore's Personal Data Protection Act (PDPA).
- Independent penetration testing, enterprise access controls such as single sign-on (SSO) and multi-factor authentication (MFA), and formal compliance documentation are active items on our security roadmap.
We support enterprise due diligence — including reviews by financial institutions and other regulated organizations — with detailed, control-by-control documentation under NDA. Talk to your JobKred contact to get started.
Related
- Account & access — roles, sharing, and sessions
- FAQ — common questions, including security and privacy
- Billing & payments FAQ