Security & Privacy

Sensitive family information deserves serious protection.

Josda handles information that may include financial details, estate records, uploaded documents, and other sensitive personal information. Security and privacy are built into how the platform is operated, how access is controlled, and how customer information is handled.

Protecting customer information

Security starts with protecting the data itself.

Josda uses technical and access controls designed to protect customer information while it is stored, transmitted, and used within the platform.

Encryption

Encrypted in transit and at rest.

Josda encrypts Customer Data while it moves between systems and while it is stored.

Data isolation

Customer records are logically separated.

Josda uses logical segregation and row-level security or equivalent application and database controls to isolate customer records.

Access control

Production access is restricted.

Administrative access to production systems is limited to authorized personnel with a legitimate operational need. Customer access requires multi-factor authentication or equivalent identity verification during initial login and account setup.

Cloud infrastructure

Built on established cloud infrastructure.

Josda’s production environment is hosted in AWS and relies on established infrastructure providers for foundational cloud and data-center protections.

Secure operations

Protection goes beyond encryption.

Security also depends on how software is built, changed, monitored, and recovered when something goes wrong.

Controlled development

Source-code access is restricted, and code and infrastructure changes are maintained through version-controlled workflows.

Logging & tracing

Josda maintains production logging, event logging, and tracing to support operational troubleshooting, incident investigation, and security review.

Incident response

Josda maintains documented procedures for assessing, containing, investigating, remediating, and documenting security incidents.

Continuity & backup

Critical production data is backed up automatically multiple times per day, with current backup retention configured for 30 days. Josda also maintains a written Business Continuity / Disaster Recovery Plan.

Privacy & responsible AI

AI should assist the work without taking over the decisions.

Josda’s AI-enabled functionality is designed to help users work with information in their estate-planning experience while limiting the use of customer information to the requested function.

Read our Privacy Policy
01

Limited data use

Customer information submitted to AI-enabled functionality is limited to what is necessary to provide the requested functionality.

02

No training on customer personal information

Josda does not use customer personal information to train its own AI models.

03

Assistive, not autonomous

AI output is intended to assist the user and is subject to human review where appropriate. Josda does not use AI for automated decision-making or profiling.

Security governance

Security is supported by documented policies and procedures.

Josda maintains a written security and privacy program covering the operational areas that matter to protecting customer information, responding to incidents, maintaining continuity, and managing data throughout its lifecycle.

  • Written Information Security Program (WISP)
  • Incident Response Plan
  • Business Continuity / Disaster Recovery Plan
  • Data Retention, Backup, and Secure Deletion Standard
  • Vendor and subprocessor oversight

These materials help support customer security, compliance, legal, and vendor-management diligence.

For security & compliance teams

Need to go deeper?

Advisory firms may need to evaluate Josda through their own security, compliance, legal, or vendor-management process. We can provide additional security materials and respond to diligence questions as appropriate.