Security and data control as a baseline.
Jurono is for firms that need clear answers on data, access, audit trails, and GDPR before adopting new software.
Implemented today#
Dated roadmap#
Security firms can evaluate#
For Jurono, security is not just reassurance. It is a buying criterion. Firms need to understand who has access, which actions are traceable, how data is protected, and which controls hold up in daily work.
Reviewable today
Authentication, role-based guards, mandate context, audit logs, consent records, and PII redaction are the baseline firms can review today.
Separated roadmap
Open security work is not sold as finished protection. Provider verification, production ClamAV evidence, RLS decisions, backup restore drills, retention lifecycle proof, and encryption at rest remain blockers or dated roadmap items.
Review rule
Page owner: Product + Security. This page is reviewed after each closed security backend issue from #53 through #61.
Security architecture in daily work#
1. Secure access
Authentication, secure password handling, session logic, and security events protect access to the platform.
2. Make actions traceable
Audit logs document relevant access and changes, so firms are not left guessing when something needs to be reviewed.
3. Protect data
Access controls, PII redaction, and separate blockers for upload checks reduce risk around confidential content without presenting missing controls as implemented.
4. Improve controls
Roadmap controls carry quarter and year, so procurement, privacy, and product development share the same expectation.
Security and procurement assets#
Security one-pager
One-page facts on hosting, transport encryption, access, and audit logs. Request one-pager →
Data protection & DPA
Roles, DPA, TOMs, subprocessors, transfers, export, deletion, and blockers. Read procurement page →
TOM overview
Technical and organisational measures for data protection officers and IT contacts. Request TOM overview →
Subprocessor list
Overview of subprocessors involved in processing. Request list →
Hosting & backups
Location, infrastructure, backup rhythm, and retention at a glance. Request overview →
Controls roadmap
Implemented controls and Q4 2026 security work. Request roadmap →