Security & Compliance

Enterprise security isn't a checkbox.
It's the architecture.

Your operational data stays inside our SOC 2-audited AWS infrastructure. Our AI runs on AWS Bedrock inside a VPC with no public internet exposure. Your data is never used to train models. Every action is auditable.

AWS Bedrock — AI inside your security boundary

Most vendors bolt on AI by sending your data to third-party APIs. GearJoT is different.

🔒

VPC Isolated

Model invocations inside our VPC via PrivateLink. No public internet.

🚫

No Training

AWS does not train on your data. Contractual guarantee.

📋

Full Audit Trail

Every AI call logged in CloudTrail. Who, when, what model, what context.

🛡️

PII Redaction

Automatic redaction of sensitive data before model processing.

Encryption & network isolation

Encryption Everywhere

  • At rest: AES-256 with AWS KMS customer-managed keys
  • Internal transit: TLS 1.2+ over PrivateLink
  • External transit: TLS 1.3 at the load balancer
  • AI payloads: never persisted — processed in memory, discarded
  • Audit logs: encrypted in dedicated storage

Network Isolation

  • • Private VPC with no direct public internet for internal services
  • • AI routes through VPC endpoints (PrivateLink)
  • • Security groups restrict service-to-service traffic
  • • All external access through hardened load balancers
  • • Multi-tenant isolation at the database level

Compliance frameworks

SOC 2 Type II
Designed & planned
ISO 27001
AWS in scope
FedRAMP
AWS GovCloud
HIPAA
BAA eligible
GDPR
EU deployment
ITAR
GovCloud support

Access control

Role-Based Permissions

Six role tiers from Field Worker (minimal, task-focused) to Admin (full configuration). Each role has defined capabilities — no ambiguity.

Field-Level Permissions

Cost fields visible only to supervisors. Customer notes editable only by account managers. Compliance fields locked after record closure.

Record-Level Access

Ownership-based, relationship-based, or status-based. "See only your records." "External collaborators see only their customer's records."

External Collaboration Scopes

Bring in dealers, OEMs, and partners with scoped access. They see only what's shared — specific assets, issues, channels. Internal ops stay private.

For enterprise procurement

When your security team asks:

"Where is our data processed?" → Your chosen AWS region, inside our VPC

"Is data used to train AI?" → No. Contractually prohibited.

"SOC 2 documentation?" → Yes. Infrastructure designed, audit planned.

"Does AI data leave your infra?" → No. VPC PrivateLink only.

"Full audit trail?" → Every action, every AI call, every field change.

"SSO support?" → Yes, via WorkOS (SAML, OIDC).