How Jabeco keeps your data safe
Jabeco holds your product plans, so how it keeps them is a fair first question. This page says what is in place today, specifically, and who to write to about it.
Where your data lives
Jabeco runs on Vercel, which hosts the application, and Supabase, which provides the Postgres database and sign-in. The production database is in the United States, in the US East (us-east-1) region.
Your workspace is walled off at the database
Every table in Jabeco’s database has Postgres row-level security turned on. Your workspace’s data can be read only by members of your workspace, and that rule is enforced by the database itself, not only by application code. Tests that try to read across workspaces run against a real database before every change ships.
Inside a workspace, each person has a role (owner, editor or viewer) that decides what they can change.
Encryption
Everything between your browser and Jabeco travels over HTTPS (TLS). Stored data is encrypted at rest by Supabase, which is the standard on its platform.
Backups
The production database is backed up every night. Each backup is encrypted (AES-256) before it is stored and is kept for 30 days. Every backup is also restore-verified: each night it is loaded into a fresh database and every table’s row count is checked against the original before the backup is kept.
Payments
Payments are handled by Stripe. You enter your card on Stripe’s own checkout and billing pages, so Jabeco never sees or stores a card number.
AI and your data
Jabeco’s AI features run on Anthropic’s API. When you run an AI action, Jabeco sends Anthropic the part of your workspace that action needs — for example, the backlog items being scored — and nothing from any other workspace. Jabeco does not train AI models on your content.
Anthropic’s Commercial Terms of Service say that Anthropic does not train its models on content sent through its API by commercial customers like Jabeco.
Sub-processors
The providers that process your data to run Jabeco, as listed in the privacy policy.
- Supabasedatabase and authentication hosting
- Vercelapplication hosting
- Resendtransactional email delivery
- Stripepayment processing
- PostHogproduct analytics (once enabled)
- GitHubencrypted nightly database backups, and the optional GitHub integration
- CloudflareDNS and forwarding of email sent to Jabeco
- Anthropicpowers Jabeco’s AI features (e.g. prioritization); your roadmap/backlog content is sent to Anthropic’s API to generate those results
Reporting a vulnerability
Found a security issue? Email matt@jabeco.app. The founder reads it directly. Please include how to reproduce it, and give us a chance to fix it before telling anyone else.
Compliance and questionnaires
Jabeco does not hold a SOC 2 report of its own yet. The providers it runs on (Vercel, Supabase, Stripe, Anthropic, Resend, GitHub and Cloudflare) each hold a SOC 2 Type II report. If your company needs a security questionnaire answered, email it to matt@jabeco.app.