JarvisX

Detailed Security Review

Diligence answers aligned with the Cloud Security Alliance (CSA) CAIQ v4 domains, compiled for procurement audits.

1. Authentication & access management

Is SSO supported?

Compliant

Google OAuth 2.0 (OIDC) is supported for self-serve users. SAML 2.0 federation is standard on the Enterprise tier. It integrates with Microsoft Entra ID (Azure AD), Okta, Ping Identity, and ADFS.

Is MFA supported?

Compliant

We inherit MFA configurations enforced by your identity providers (SSO/SAML/Google). We do not store passwords, meaning all verification flags run through your existing security checkpoints.

Is role-based access control enforced?

Compliant

Yes. Workspace-level roles include Owner, Editor, and Viewer. RBAC is verified in application middlewares and database query rules.

Are passwords stored on your side?

Compliant

No. Authentication is fully passwordless via magic email links, Google SSO, and SAML integrations.

2. Data handling & retention

What data do you collect?

Compliant

We collect uploaded code files/queries solely to modernize them. Metadata like transaction counts, workspace configuration, and audit security events are stored. Code structures are never used to train public LLM agents.

Is data deleted on account closure?

Compliant

Yes. Accounts undergo a 30-day soft-delete period, followed by complete physical erasure from all active servers. Backups are overwritten on a rolling 30-day cycle.

Can data be pinned to a region?

Partial

All data is hosted inside Google Cloud’s us-central1 region. EU region pinning can be set up for Enterprise customers on request.

3. Encryption

Is data encrypted in transit?

Compliant

TLS 1.3 is enforced on all ingress APIs. Internal micro-service endpoints communicate via Google’s TLS envelopes. Downgrade requests are blocked.

Is data encrypted at rest?

Compliant

AES-256 encryption is applied via GCP defaults. KMS Customer-Managed Encryption Keys (CMEK) can be provisioned on Enterprise.

4. Secure SDLC

Is code reviewed before deployment?

Compliant

Yes. All codebase modifications require pull request reviews by certified senior developers and clear automated validation pipelines before shipping.

Are dependencies scanned for vulnerabilities?

Compliant

Yes. Automated scanners inspect dependencies daily. High and critical CVEs trigger build halts and patch requirements.

Diligence & Custom Surveys

Our compliance team reviews and completes custom security spreadsheets within 48 business hours.

Submit Survey File