Trust Center

Our own security posture, public and provable.

This page mirrors what every Joopler customer gets out of the box: a public Trust Center with frameworks, security overview, subprocessors, and gated document requests.

SOC 2HIPAAISO 27001PCI DSSISO 42001NIST 800-53OSCAL-native

Framework status shown here is illustrative.

Security overview

A short summary of how we operate.

Data protection

TLS 1.2+ in transit, AES-256 at rest, per-tenant KMS keys for evidence signing.

Access

SSO + MFA required for all Joopler personnel. Least-privilege, quarterly access reviews.

Isolation

Row-level and object-storage tenant isolation. WORM evidence with retention locks.

We run our own compliance on Joopler.

Joopler is its own tenant: we manage our security program on the same platform we sell, and every artifact is signed and independently verifiable, so you never have to take our word for it. Our SOC 2 is in progress; we will publish the report here once an independent auditor has issued it, not before.

Subprocessors

Who we rely on to run Joopler.

VendorPurposeRegion
Amazon Web ServicesCloud infrastructure & WORM object storageUS
VercelApplication hosting & edge deliveryGlobal
ClerkAuthentication & user identityUS
StripeBilling & paymentsUS
ResendTransactional emailUS
SentryError monitoringUS

We keep this list current and update it as our subprocessors change.

Documents

Request our security documentation.

Security whitepaper

Public download

DPA & Subprocessor list

Public

Document requests are gated by a short form. Illustrative flow, no live downloads.

Give your customers this same page.

Every Joopler tenant gets a public, white-labelable Trust Center out of the box.