Trust Center

Security Overview

A layered approach to protecting I am J systems, services, deployments, and information.

Status: Published
Version: 1.0
Effective date: July 15, 2026
Contact I am J
Security is a shared and continuous responsibility across product design, software development, cloud operations, enterprise deployment, vendor management, and user support.
I am J Corporation applies layered safeguards intended to reduce the likelihood and impact of unauthorized access, misuse, disruption, data loss, and other security events.
01

Security Program

Our security program is risk-based and evolves with our technology, threat environment, service maturity, customer needs, and applicable obligations.

Controls are selected according to the sensitivity of data, criticality of systems, deployment model, and reasonably foreseeable impact.

02

Secure Architecture and Engineering

Security considerations are incorporated into architecture, implementation, testing, release, and maintenance activities.

  • Use managed identity, authentication, and authorization controls where appropriate.
  • Apply least-privilege access to systems and data.
  • Separate environments and responsibilities where practical.
  • Protect secrets and credentials from unauthorized disclosure.
  • Review dependencies and remediate material vulnerabilities according to risk.
03

Encryption and Data Protection

We use encryption and secure transport mechanisms where appropriate to protect data in transit and at rest.

Encryption is one component of a broader control environment that also includes access control, monitoring, retention practices, backups, and secure configuration.

04

Identity and Access Management

Access to corporate and production resources should be limited to authorized users with a legitimate business need.

Controls may include unique identities, multi-factor authentication, role-based permissions, access reviews, session controls, and prompt removal of access when no longer required.

05

Cloud and Operational Security

Operational safeguards may include hardened configurations, logging, monitoring, alerting, backup practices, change control, capacity management, and recovery procedures.

System configurations and controls are reviewed and improved as risks, technologies, and service requirements evolve.

06

Secure Development Practices

Development practices may include peer review, testing, dependency review, environment separation, source control protections, and release procedures proportionate to the risk of the change.

Security defects are prioritized according to exploitability, exposure, affected data or functionality, and potential impact.

07

Enterprise and Edge Security

J-Spark Nexus and other enterprise deployments can introduce physical, connectivity, administrative, and local-environment risks.

Deployment security may include device configuration, administrative controls, physical safeguards, network segmentation, update procedures, customer responsibilities, and documented operating guidance.

08

Third-Party Security

We depend on selected third-party infrastructure and service providers. Relevant security, reliability, privacy, and continuity risks are evaluated proportionately.

No third-party service eliminates risk; therefore, architecture and operational planning should account for dependency failures and changed provider conditions.

09

Incident Response

We maintain processes for reporting, triaging, investigating, containing, remediating, and learning from suspected security incidents.

Notifications to affected parties, customers, authorities, or partners are made when required by law, contract, or responsible risk management.

10

User and Customer Responsibilities

Users and customers should protect credentials, maintain supported devices, apply security updates, configure integrations carefully, and report suspicious activity.

Enterprise customers are responsible for controls within their own environments unless a written agreement assigns responsibility otherwise.

11

Responsible Security Reporting

Security researchers and users should report suspected vulnerabilities through our official contact channel and avoid actions that compromise privacy, availability, safety, or data integrity.

We ask reporters to provide sufficient detail for investigation and to allow reasonable time for remediation before public disclosure.

12

Questions and Contact