Our own security posture, public and provable.
This page mirrors what every Joopler customer gets out of the box: a public Trust Center with frameworks, security overview, subprocessors, and gated document requests.
Framework status shown here is illustrative.
A short summary of how we operate.
Data protection
TLS 1.2+ in transit, AES-256 at rest, per-tenant KMS keys for evidence signing.
Access
SSO + MFA required for all Joopler personnel. Least-privilege, quarterly access reviews.
Isolation
Row-level and object-storage tenant isolation. WORM evidence with retention locks.
We run our own compliance on Joopler.
Joopler is its own tenant: we manage our security program on the same platform we sell, and every artifact is signed and independently verifiable, so you never have to take our word for it. Our SOC 2 is in progress; we will publish the report here once an independent auditor has issued it, not before.
Who we rely on to run Joopler.
| Vendor | Purpose | Region |
|---|---|---|
| Amazon Web Services | Cloud infrastructure & WORM object storage | US |
| Vercel | Application hosting & edge delivery | Global |
| Clerk | Authentication & user identity | US |
| Stripe | Billing & payments | US |
| Resend | Transactional email | US |
| Sentry | Error monitoring | US |
We keep this list current and update it as our subprocessors change.
Request our security documentation.
Security whitepaper
Public download
DPA & Subprocessor list
Public
Document requests are gated by a short form. Illustrative flow, no live downloads.
Give your customers this same page.
Every Joopler tenant gets a public, white-labelable Trust Center out of the box.