The detail behind the trust page. What's signed, what's available, what's documented. This page is what your DPO and security review will read.
If it isn't on this page it isn't a JSE commitment. We don't list certifications we don't hold or paths we haven't started.
Every request entering JSE is tagged with an active tier before it touches a model. The tier is set per-workspace (and overridable per-run by an admin). The gateway evaluates the model registry against the tier policy:
A request to a model outside the active tier returns 400 model_not_compliant with the policy ID that rejected it. Nothing leaves the gateway, nothing is logged downstream.
An eval run stores its prompt set, the models requested, and the compliance tier it was submitted under. A cell in that run — one prompt against one model — stores:
Some things are worth stating as absences, because a reader may expect them: JSE does not compute a cryptographic fingerprint of an eval prompt, does not store which provider or datacenter served the inference, and does not store a cost in EUR against an eval run.
Eval and audit logs are retained for the lifetime of the user account; users can request export or deletion at any time per GDPR Art. 15 / Art. 17; deletion removes the record from live systems, and copies can persist in infrastructure backups after deletion. Default retention policy and longer compliance retention can be specified in the contractual DPA.
30-day notice before any new sub-processor is added. You can object; if we can't accommodate, contract terms allow termination without penalty.
Material incident notification within 72 hours of detection, regardless of contractual tier. Status page and changelog reflect post-mortems publicly when customer data is involved.
Request the full Trust Pack (signed DPA template, SCCs, security white-paper) at support@justsmarter.ai. We answer within two business days.
Send us your questionnaire. We answer in plain language, with evidence attached, within two business days.