Security built into the platform
The same controls that run our production API, summarized for your security team. For the full picture, read our Security overview.
Encrypted in transit
All traffic to the Service is encrypted with HTTPS/TLS. Data stored by our cloud providers is protected by their platform encryption.
Per-account isolation
Customer Content is logically isolated per account and processed only to provide the Service, as described in our Privacy Policy.
OAuth 2.0 & scoped keys
The API and MCP server use OAuth 2.0 with short-lived tokens. API keys are scoped to your account and can be created, rotated, and revoked.
Redundant infrastructure
The Service runs on Google Cloud, Vercel, and Cloudflare, with redundant infrastructure, backups of critical data, and availability monitoring.
Compliance and procurement, handled
The documents and terms your legal, security, and procurement teams ask for.
DPA & sub-processors
We make a Data Processing Addendum available to customers who need one, and we publish our full sub-processors list.
Read the DPAGDPR & US privacy laws
We honor data-subject rights under the GDPR and US state privacy laws, including CCPA/CPRA, as described in our Privacy Policy.
Security overviewEnterprise agreements
Specific service-level commitments, retention terms, and security requirements are set out in a signed enterprise agreement scoped to your needs.
Talk to usOne engine for every branded asset
Marketing images, personalized cards, dashboards, and data visualizations, all from a single API and template library.
One API, any stack
A single sync render endpoint (GET or POST) with key-based auth, ready-to-use code examples for 30+ languages and frameworks, an MCP server for AI agents, and Zapier / Sheets / Airtable connectors.
20+ data-viz components
Charts, KPI tiles, tables, heatmaps, QR and barcodes: render dashboard-quality cards, not just text on images.
Built for volume
Design a template once, then generate thousands of on-brand images, charts, and cards from your own data without a render pipeline to maintain.
Enterprise FAQs
Do you offer a Data Processing Addendum (DPA)?
Yes. We make a DPA available to customers who need one, and we publish our full sub-processors list so your legal and security teams can review who processes data on our behalf.
Where is our data hosted, and how is it protected?
The Service runs on established cloud providers, including Google Cloud Platform, Vercel, and Cloudflare. Traffic is encrypted in transit with HTTPS/TLS, data at rest is protected by our providers' platform encryption, and Customer Content is logically isolated per account.
Do you offer an uptime SLA?
We use managed, redundant cloud infrastructure with backups and availability monitoring, and we aim for high availability. Specific service-level commitments, if any, are set out in a signed enterprise agreement.
How do you handle authentication and API access?
The API and MCP server use OAuth 2.0 with protected-resource metadata and short-lived access tokens. API keys are scoped to your account and can be created, rotated, and revoked. Internal access to production systems follows the principle of least privilege.
Can we complete a security review before purchasing?
Yes. Start with our public Security overview, DPA, and sub-processors list, then email support@imejis.io with your security questionnaire and requirements and we'll work through them with you.
What does enterprise pricing look like?
Enterprise plans are custom: a committed base plus volume-based render pricing sized to your expected usage, with terms scoped to your security, retention, and support needs. Talk to us for a quote.
Let's scope an enterprise plan
Tell us about your organization, your volume, and your security and compliance requirements. We'll put together an agreement that fits.