Draft — pending legal review. This document is not yet binding.
Taslak — hukuk incelemesi bekliyor. Bu metin henüz bağlayıcı değildir.
Last updated: 2026-07-05
How JARA approaches the security of its products and how to report an issue responsibly.
The English version of this document will be authoritative once finalized. · Bu belgenin İngilizce sürümü, son hâline geldiğinde bağlayıcı sürüm olacaktır.
Security is expected to be built into how JARA products are designed and operated, with data encrypted in transit and at rest. This section will describe our practices for access control, monitoring, and secure development in more detail once finalized.
JARA does not currently hold a SOC 2 Type II attestation and does not offer a contractual uptime SLA. Independent attestation, regional data residency, SSO and SCIM, and a custom DPA are on our roadmap for Enterprise, and this page will be updated when each is in place rather than in advance of it. What is true today: data is encrypted in transit and at rest, and your private content is never used to train models.
If you believe you have found a security vulnerability, please report it to security@heyjara.app. Our machine-readable contact details are published at /.well-known/security.txt. Please give us a reasonable opportunity to investigate and remediate before any public disclosure.
This section will set out what to expect after a report — acknowledgement, triage, and status updates — once the process is finalized. We ask that testing avoids privacy violations, service disruption, and access to data that is not your own.