Security - Jam Documenation

Compliance and certifications

Certification Status
SOC 2 Type II Compliant. Annual audits, quarterly vulnerability assessments
GDPR Compliant
HIPAA Coming soon

To request the SOC 2 Type II report, email security@jam.dev with your company information and intended use. The security team will verify your qualifications and provide the report.

Data storage and infrastructure

Frequency Retention
Hourly 2 days
Daily 7 days
Weekly 4 weeks
Monthly 12 months

All cloud services, source code access, and third-party tools are secured with two-factor authentication.

Data privacy

Where recordings are stored Jam stores all recordings in Google Cloud Platform. Jam does not currently support redirecting recordings to your own storage solution. Data retention Jams don’t expire. A Jam stays available until someone deletes it, or until the account or workspace it belongs to is deleted - nothing is deleted automatically through inactivity. When you delete a Jam, it isn’t hard-deleted immediately, it’s archived first. If a workspace is archived, its data enters a 90-day window, after which an automated clean-up job permanently deletes it and all associated data. Jams created by a member who leaves or deletes their own account stay with the workspace - that content is only permanently deleted when the entire workspace is closed. Enterprise customers can set a custom data deletion schedule for their workspace. Contact Jam to configure your preferred schedule. Consent An end customer must actively choose to start a recording and then submit it before any visual or browser data is stored by Jam. Both steps are explicit consent actions that the user can decline.

Sensitive data handling

Jam includes two protections to minimize the sensitive information collected during recordings:

AI policy

Jam AI features are powered by third-party AI models. Here is how Jam handles your data when AI is involved:

Jam AI (ticket creation, reproduction step generation) uses Google Gemini and is opted out of model training. The AI Debugger feature uses the OpenAI API. OpenAI does not train on data sent through the API. You can manage AI features in Settings.

Enterprise security features

The following features are available on the Enterprise plan. Contact sales to upgrade.

Security monitoring

Vulnerability testing: Jam performs quarterly vulnerability scans and annual penetration tests as required by SOC 2 Type II compliance. GitHub’s dependency vulnerability feed monitors third-party dependencies in Jam’s source code continuously. Intrusion detection: Jam uses Cloudflare for attack prevention and GCP firewalls for infrastructure protection. Because the production network is fully managed by GCP, Jam does not run a separate IDS/IPS. Incident response: The security team reviews reports immediately and notifies affected users of confirmed incidents.

Contact security

For security questions, vulnerability reports, or to request the SOC 2 report, email security@jam.dev. The team responds as quickly as possible and keeps you updated throughout any investigation. Jam does not currently offer a bug bounty program.