SecuritySecurity

Last updated: July 26, 2026

Security is central to how we build and run Imejis.io (JAGODANA LLC). This page gives an overview of our practices. It is a summary, not a warranty; for contractual data-protection terms see our Data Processing Addendum.

InfrastructureInfrastructure

The Service runs on established cloud providers, including Google Cloud Platform, Vercel, and Cloudflare. See our full Sub-processors list. We rely on these providers' physical, network, and platform security controls.

EncryptionEncryption

All traffic to the Service is encrypted in transit using HTTPS/TLS. Data stored by our cloud providers is protected by their platform encryption. We do not store full payment card numbers; payments are handled by our PCI-compliant processor, Stripe.

Authentication and accessAuthentication and access

  • The API and MCP server use OAuth 2.0, with protected-resource metadata and short-lived access tokens.
  • API keys are scoped to your account and can be created, rotated, and revoked.
  • Internal access to production systems is limited to personnel who need it, and we follow the principle of least privilege.

Data handlingData handling

Customer Content is logically isolated per account. We process content to provide the Service (design, storage, and rendering) as described in our Privacy Policy. We retain and delete data as described there.

Availability and resilienceAvailability and resilience

We use managed, redundant cloud infrastructure and maintain backups of critical data. We monitor the Service for availability and errors. We aim for high availability; specific service-level commitments, if any, are set out in a signed enterprise agreement.

Responsible disclosureResponsible disclosure

If you believe you have found a security vulnerability, please report it to support@imejis.io. Our machine-readable contact is published at /.well-known/security.txt. We ask that you give us a reasonable opportunity to remediate before public disclosure, and we will not pursue researchers who act in good faith.

ComplianceCompliance

We honor data-subject rights under the GDPR and US state privacy laws (including CCPA/CPRA) as described in our Privacy Policy, and we make our DPA available to customers who need one. For enterprise security or compliance questions, contact support@imejis.io.