Joya handles contracts, invoices, and rate cards — documents that matter. Here's how we protect them.
Original documents are deleted from our systems immediately after processing. Only the structured, human-reviewed results are kept.
Documents are processed via commercial API terms with Anthropic (Claude), which explicitly exclude customer data from model training.
Every table is protected by database-level Row Level Security, scoped to your organisation and department. Enforced by the database itself, not just application code.
Data is encrypted at rest (AES-256) and in transit (TLS) across every system in our stack.
Supabase (database, storage, authentication) — SOC 2 Type 2, ISO/IEC 27001:2022, HIPAA, PCI DSS
Anthropic (AI processing) — SOC 2 Type I & II, ISO 27001:2022, ISO/IEC 42001:2023
Stripe (payments) — PCI-DSS Level 1
Cloudflare (hosting and delivery)
Need the full technical detail for a security review — RLS policies, credential handling, data retention specifics, and known limitations?
Request our security documentation