Security
Your work stays your organization’s.
Written for the person who has to sign off. Four questions, one line each — then the rules behind every line, each one enforced in the product rather than promised in a policy.
- Where does it run?
- On your organization's own server. Accounts, records and files belong to it.
- Who holds the keys?
- You. Provider keys are sealed on the way in and never read back out.
- What leaves the building?
- Nothing by itself. A send, a publish or a payment waits for a person.
- What is the audit trail?
- One ledger of what ran, for whom and why — people and crew alike.
The rules
Five rules, each with what enforces it.
If a rule has an exception, the product says so where it happens.
- 01
Your server, your accounts
- Jeeraph is served by your organization's own server. Accounts, projects and files belong to it.
- There is no Jeeraph-hosted account service between your people and their work.
- Records live in PostgreSQL and file bytes in your object storage.
- 02
Access that only narrows
- Access and allowed types pass down from portfolio to project to package. A level can narrow what it inherits, never widen it.
- An empty permission requirement means deny, not allow.
- Identity comes from a revocable browser session checked on every request — never from a header a caller controls.
- 03
Credentials that never come back out
- Provider keys an organization connects are sealed with AES-GCM before they are stored. They go in; they are not read back to a browser.
- Server secrets live in a secret manager, not in configuration files or source.
- Two-factor sign-in with authenticator codes and recovery codes; people can see and end their own sessions.
- 04
AI that is budgeted and gated
- Model spend defaults to deny. Every call reserves budget before it runs.
- Crew actions pass through one gate and are written to one ledger of what ran, for whom and why.
- A crew member drafts and proposes; the person it works for decides.
- 05
Failures that say so
- When required work fails, the product says it failed. Degraded is a state, not a silent success.
- A number the product cannot stand behind is not shown as a number.
Questions for your reviewer?
Ask Jeeraph where it runs and who holds the keys, or book thirty minutes with an engineer about your environment.