Back to Joya

Trust and Security

Joya handles contracts, invoices, and rate cards — documents that matter. Here's how we protect them.

Stateless by design

Original documents are deleted from our systems immediately after processing. Only the structured, human-reviewed results are kept.

No AI training on your data

Documents are processed via commercial API terms with Anthropic (Claude), which explicitly exclude customer data from model training.

Isolated per customer

Every table is protected by database-level Row Level Security, scoped to your organisation and department. Enforced by the database itself, not just application code.

Encrypted throughout

Data is encrypted at rest (AES-256) and in transit (TLS) across every system in our stack.

Built on certified infrastructure

Supabase (database, storage, authentication) — SOC 2 Type 2, ISO/IEC 27001:2022, HIPAA, PCI DSS

Anthropic (AI processing) — SOC 2 Type I & II, ISO 27001:2022, ISO/IEC 42001:2023

Stripe (payments) — PCI-DSS Level 1

Cloudflare (hosting and delivery)

Need the full technical detail for a security review — RLS policies, credential handling, data retention specifics, and known limitations?

Request our security documentation