Security
Overview
Jensi connects Slack, Teams, Gmail, Outlook, and meetings into a reviewable work intelligence layer. That means we handle sensitive workplace data — so security is part of how the product is built, not an afterthought.
This page summarizes the independent assessments, infrastructure certifications, and product controls that protect customer data. For how we collect and use information, see our Privacy Policy.
Google CASA Tier 2
Jensi has completed Google's Cloud Application Security Assessment (CASA) Tier 2, an independent review by an App Defense Alliance authorized assessor. CASA is based on the OWASP Application Security Verification Standard (ASVS) and is required for apps that access restricted Google APIs.
Our Google integration uses read-only scopes (including Gmail and Drive) and has completed Google OAuth app verification, so customers connect through a verified consent experience.
- Independent validation: Third-party lab assessment, not a self-attestation alone
- Annual revalidation: CASA Tier 2 requires yearly renewal to stay current
- Scope: Security controls for our application and infrastructure that process Google user data
Infrastructure SOC 2
Our cloud infrastructure providers maintain SOC 2 Type II certification. Customer data is hosted in secure data centers operated by providers that meet this standard.
This is distinct from a SOC 2 report issued for Jensi as an organization. Provider certification covers the underlying infrastructure; see Compliance roadmap for our product-level plans.
Product Controls
Alongside assessments and provider certifications, Jensi enforces controls in the product itself:
- Encryption: TLS 1.3 in transit and AES-256 at rest
- Access controls: Authentication requirements and organization-scoped permissions
- Human approval: Suggestions require review before becoming tracked work
- Source attachment: Every suggestion links back to the Slack or Teams thread, email, or meeting it came from
- Auditable history: Who asked, who approved, and what changed stays on the record
- Regular security work: Ongoing security reviews and penetration testing as part of our release process
Compliance Roadmap
A SOC 2 Type II audit for Jensi as an organization is on our roadmap. Until that engagement completes, we do not claim that Jensi itself is SOC 2 certified. We continue to rely on SOC 2 Type II certified infrastructure providers and our completed CASA Tier 2 assessment for Google.
Contact
Security questions, vulnerability reports, or compliance requests:
- Email: hello@jensi.io