Security and data control as a baseline.

Jurono is for firms that need clear answers on data, access, audit trails, and GDPR before adopting new software.

Today
Auth, roles, audit, log protection
Traceability
Audit logs for core events
Roadmap
Dated Q4 2026
Owner
Product + security review

Implemented today#

Server location
Unclear provider chains
Production providers are named in the DPA appendix; this repo state does not prove the full provider register
Transport
Unclear transfer security
HTTPS/TLS is required for public deployments; concrete edge configuration is verified on production
Access
Shared or weak accounts
Argon2id password hashing with bcrypt migration, JWT sessions, logout, and role-based guards
Mandate context
Mandate data without clear boundaries
Tenant context, role checks, and object-level access controls in core modules
Logging
No later review possible
Audit logs for mandates, documents, privacy, and consent events
Log protection
Personal data in logs
PII redaction for structured server logs
DPA
Contract review blocked
Available on request for contract review

Dated roadmap#

Backups
Baseline operations
Evidence register exists; production restore drill and lifecycle proof still block unrestricted sensitive use
Upload protection
Baseline upload
ClamAV fail-closed baseline is required in production; health and EICAR evidence still gate unrestricted sensitive uploads
Encryption at rest
Transport encryption
AES-256-GCM for especially sensitive communication and file content: Q4 2026
Token and auth hardening
Existing JWT and session logic
Separated secrets, hashed reset/API tokens, refresh reuse detection: Q4 2026
MFA protection
MFA functionality
Envelope encryption for TOTP secrets and hashed backup codes: Q4 2026
Tenant isolation
Guards and object checks
RLS decision and fresh-database hardening after #53: Q4 2026
SOC 2
Internal control orientation
Report or certification: after Q4 2026

Security firms can evaluate#

For Jurono, security is not just reassurance. It is a buying criterion. Firms need to understand who has access, which actions are traceable, how data is protected, and which controls hold up in daily work.

Implemented

Reviewable today

Authentication, role-based guards, mandate context, audit logs, consent records, and PII redaction are the baseline firms can review today.

Q4 2026

Separated roadmap

Open security work is not sold as finished protection. Provider verification, production ClamAV evidence, RLS decisions, backup restore drills, retention lifecycle proof, and encryption at rest remain blockers or dated roadmap items.

Owner

Review rule

Page owner: Product + Security. This page is reviewed after each closed security backend issue from #53 through #61.

Security architecture in daily work#

  1. 1. Secure access

    Authentication, secure password handling, session logic, and security events protect access to the platform.

  2. 2. Make actions traceable

    Audit logs document relevant access and changes, so firms are not left guessing when something needs to be reviewed.

  3. 3. Protect data

    Access controls, PII redaction, and separate blockers for upload checks reduce risk around confidential content without presenting missing controls as implemented.

  4. 4. Improve controls

    Roadmap controls carry quarter and year, so procurement, privacy, and product development share the same expectation.

Security and procurement assets#

Security one-pager

One-page facts on hosting, transport encryption, access, and audit logs. Request one-pager →

Data protection & DPA

Roles, DPA, TOMs, subprocessors, transfers, export, deletion, and blockers. Read procurement page →

TOM overview

Technical and organisational measures for data protection officers and IT contacts. Request TOM overview →

Subprocessor list

Overview of subprocessors involved in processing. Request list →

Hosting & backups

Location, infrastructure, backup rhythm, and retention at a glance. Request overview →

Controls roadmap

Implemented controls and Q4 2026 security work. Request roadmap →

Read data protection and DPA Request security one-pagerHome