Security and Data Governance | Just Society Technologies

For security reviewers and procurement

What is in place today, and what is not yet.

Government buyers need a technical answer alongside the ethical one. This page states both, and separates them honestly. Stewardship covers what we refuse to do. This covers how the platform is built and governed.

We do not claim certifications we do not hold. Items marked on the roadmap are exactly that. A security reviewer can request the current overview and we will send it with dates attached.

01 / Controls

Filter by status.

Eighteen controls. Ten in place, eight on the roadmap.

In place

Hosting

Managed cloud infrastructure in United States regions, with environment separation between development and production.

In place

Encryption in transit

TLS on every connection to the platform and between services.

In place

Encryption at rest

Storage-layer encryption on all persisted data and backups.

In place

Role-based access control

Access granted by role and scoped to engagement. Least privilege by default.

In place

Multi-factor authentication

Required on all administrative and staff accounts.

In place

De-identification

Direct identifiers are separated at intake. Outputs release only above a suppression threshold.

In place

Suppression and aggregation

No individual-level record leaves the platform, to any client, under any contract.

In place

Community review gate

No findings release before the Data Stewardship Board review window closes.

In place

Retention and deletion

Retention set per engagement. Deletion requests executed and confirmed in writing.

In place

Export

Findings and dashboards exportable in open formats on request.

On the roadmap

Audit logging

Access and action logging with client-visible reporting. In build.

On the roadmap

Backups and disaster recovery

Documented recovery objectives and a tested restore procedure. In build.

On the roadmap

Incident response plan

Written plan with notification timelines and a named responsible owner. In build.

On the roadmap

Subprocessor register

Published list of vendors with data access and their review dates. In build.

On the roadmap

Penetration testing

Independent annual testing with a summary letter available to clients. Planned.

On the roadmap

SOC 2 Type II

Readiness assessment first, then audit. Planned. We will not claim a certification we do not hold.

On the roadmap

WCAG 2.2 AA

Accessibility conformance review and remediation across the platform and this site. In progress.

On the roadmap

Vulnerability disclosure

A published route for researchers to report issues. Planned.

02 / The standard we hold
A tool claiming to show the full picture must mark the edges of its own sight.

The same honesty applies to the platform underneath it. A roadmap item stated as shipped is a finding nobody can rely on.

Just Society Technologies · on disclosure
03 / Data ownership, in plain English

Who owns what, and what happens at the end.

Who owns the raw dataJST owns it, under a six-line charter anchored in our articles, our contracts and our investor documents. The charter is the limit on that ownership.
Who can see itRole-based access inside JST. Aggregate, threshold-cleared findings to the commissioning institution. Never individual records, to anyone.
Do you train models on itNo model is trained for resale or for any client other than the place the data came from.
What you keep at contract endYour findings, your dashboards and your trained research cohort stay with you. The instrument can be commissioned again.
Deletion and exportExport on request in open formats. Deletion requests are executed and confirmed in writing.
Who can stop a useThe Data Stewardship Board holds binding authority over the red lines and can roll back any output that drifts.

The six red lines in full Request the procurement pack

Send this to your reviewer.

We will provide the security overview, data governance summary and accessibility statement without a briefing first.

Request the procurement pack