Enterprise-Grade Security

Built for
CISO Approval

When the CTO says yes, the CISO takes over. Our security architecture is designed to pass vendor security reviews without friction. No production access. No data retention. No compromises.

The 4 Pillars of Data Protection

Zero Data Retention for AI

We use enterprise-grade LLM APIs (OpenAI / Anthropic) with strict Zero Data Retention agreements. Your proprietary Apex code is never used to train public models.

  • Enterprise agreements with OpenAI and Anthropic
  • Zero Data Retention (ZDR) mode enabled for all API calls
  • Your code is processed, not stored or learned from
  • No model training on customer data—ever

No Production Access Required

Jataka only needs OAuth access to your lower-level Sandboxes (Staging/Integration) to run its Kamikaze pods. We never touch your Production data.

  • OAuth scoped to Staging/Integration sandboxes only
  • Production org access never requested
  • Your customer data stays in your production org
  • Sandbox data is test data—not real customer records

Encrypted Credentials

All Salesforce OAuth tokens and GitHub access keys are AES-256 encrypted at rest and rotated automatically.

  • AES-256 encryption for all stored credentials
  • Automatic key rotation every 90 days
  • Secrets stored in AWS Secrets Manager
  • No plaintext credentials in logs or databases

Ephemeral Execution

Kamikaze Pods are ephemeral. Once a PR is tested and the limit report is generated, the Kubernetes pod and all associated memory are instantly destroyed.

  • Kubernetes pods spin up per PR, then terminate
  • No persistent storage of execution data
  • Memory cleared after each test run
  • Container isolation per customer

Compliance & Certifications

SOC 2 Type II

In Progress

Data Processing Agreement

Available

Penetration Testing

Annual

Need a specific certification or compliance document? .

How Data Flows (And Doesn't)

Your Sandbox

Test data only. No production records. Jataka profiles limits here.

Jataka K8s Pod

Ephemeral. Spins up, runs tests, generates report, destroys itself.

Your GitHub

PR comment with limit report. No code stored by Jataka.

Production Org — Never accessed| Customer Data — Never read| Model Training — Never used

Need More Details?

Our security whitepaper includes architecture diagrams, data flow maps, encryption details, and incident response procedures.

Ready for your security review?

Start the pilot.
Security Review Ready.

14-day zero-risk pilot. No production access. No data retention. Complete security documentation for your review.

Start Your Pilot