Trust

Security at Ji4

How Ji4 handles your data: EU data residency, tenant isolation, encryption, passwordless authentication, webhook security and backups.

Draft, pending legal review

This page describes Ji4's actual technical security measures, not aspirational plans. It is a draft pending review by our legal and security teams before publication. Ji4 does not currently hold any third-party security certification, such as SOC 2 or ISO 27001, or an independent penetration test, and nothing on this page should be read as claiming one.

EU data residency and GDPR posture

Ji4 is operated from Ireland, in the EU. Production data, including our database and file storage, resides on EU-based infrastructure.

We act as a data processor for the support content you bring into the product; your workspace remains the controller. A Data Processing Agreement is available covering processing terms, international transfer safeguards, and sub-processor commitments. See our sub-processor list for exactly who we work with and what each receives.

Tenant isolation

Ji4 keeps each workspace's data isolated at the data layer: every model holding workspace data is scoped through a global application-level scope, so a query cannot return another workspace's rows by accident, and background jobs carry an explicit workspace identifier rather than inferring one from ambient state.

This isolation is backed by an automated cross-tenant isolation test suite, run regularly, specifically to catch a query or job that could reach across workspace boundaries before it ships.

Encryption

All access to Ji4 is encrypted in transit using TLS. Sensitive third-party secrets stored by the product, including Linear OAuth tokens and the inbound webhook signing secret, are encrypted at rest and are never exposed to your customers or in client-side code.

Passwordless authentication

Sign-in uses passwordless, single-use magic links sent to your work email, rather than a password we would otherwise have to store. Each link is short-lived and can only be used once.

Webhook security

Inbound webhooks, including Linear status changes, are verified by signature against a signing secret before being processed. Duplicate or replayed deliveries are detected and rejected rather than reprocessed.

Rate limiting

Public endpoints, including sign-in, inbound webhooks and inbound email, are rate-limited to reduce abuse and automated attack traffic.

Backups

We take regular backups of production infrastructure and databases as part of normal operations.

The Linear OAuth model

Ji4 connects to Linear over OAuth. You authorise the connection from Linear in one click, Ji4 requests only the scopes it needs, and issues created by Ji4 are attributed to the Ji4 app. Each workspace's connection is isolated, and you can revoke access at any time from Linear or from Ji4 settings.

Your customers never touch Linear, the connection lives entirely on your side of the product.

Related: Data Processing Agreement, our sub-processor list, and the Linear integration.

Bring support into the tools
engineering already lives in

Start a 14-day trial in minutes. No card, no sales call, cancel anytime.

We use optional analytics cookies to understand how the Ji4 website is used and to improve it. See our cookie policy for details.