Your data is safe
with Jtek

Enterprise-grade security built for small businesses. Your client data stays encrypted, private, and protected.

Start free trial

Data encryption

Your data is always encrypted

All data transmitted to and from Jtek is protected by TLS 1.3. Data at rest is encrypted with AES-256. Your contacts, conversations, and files never travel unprotected. Period.

  • TLS 1.3 encryption in transit
  • AES-256 encryption at rest
  • Encrypted file storage for attachments and docs
Start secure

Role-based access

Control who sees what in your account

Set precise permissions for every team member. Admins control everything. Agents see only their contacts and pipeline. View-only users can review without editing anything.

  • Admin, Agent, and View-Only roles
  • Hide billing, reports, or team data from agents
  • Restrict contacts to assigned-only view
Manage your team

Two-factor authentication

A second layer of login protection

Enable 2FA on any account in under a minute. Every login requires both a password and a time-based code from your authenticator app, so even a stolen password can't get in.

  • TOTP-based 2FA (Google Authenticator, Authy)
  • Admin can require 2FA for all team members
  • Recovery codes provided at setup
Enable 2FA

Audit logs

A full record of every action taken

Every change in your account is logged with a timestamp and the user who made it. See when contacts were edited, when automations fired, and when settings were changed. Always.

  • Full action history with user attribution
  • Filter by user, date, or action type
  • Exportable for compliance and broker review
View audit logs

Built secure from the ground up

Every layer of Jtek is designed with your clients' privacy in mind.

SOC 2 compliant

Jtek's infrastructure follows SOC 2 Type II security controls for availability, confidentiality, and data integrity.

GDPR ready

Data subject request tools, consent tracking, and data export and deletion capabilities built in for compliance.

Data backups

Your data is backed up automatically every day with 30-day retention. Point-in-time recovery available on request.

Secure file storage

All uploaded files are stored in isolated, encrypted buckets. Client documents never share storage with other accounts.

Login monitoring

Get notified of new device logins and suspicious activity. Review login history for any account at any time.

Privacy controls

Restrict which users can export, print, or share contact data. Protect sensitive client information from accidental exposure.

FAQ

Questions about your data, answered.

Who owns the data I put into Jtek?

You do. Your contacts, conversations, files and pipeline belong to you, and Jtek processes them for one reason: to run the service you are paying for. We do not sell your personal information or your contacts' information to anyone for advertising. That is not a promise made on a marketing page, it is written into the privacy policy.

Which outside companies touch it?

Only the vendors that make the product work, and each one is contractually limited to that job: AWS for hosting, Stripe for payments, SendGrid for transactional email, Twilio for texts and calls. Card numbers go straight to Stripe and are never stored by Jtek. Anything you connect yourself, like Facebook or Google, exchanges only what you approved in the OAuth screen.

Can I stop an agent walking off with my database?

Yes, and this is the part most agents care about more than encryption. Export, print and share are permissions, not defaults. An Agent can be restricted to the contacts assigned to them, a View-Only user can read a record without changing it, and billing, reports and team data can be hidden entirely. If someone leaves your team, what they could reach is already a matter of record in the audit log.

Will I know if someone logs in from a new device?

You get notified on a new device login and on activity that looks unusual, and login history for any account is readable at any time. Failed and blocked attempts land in the same audit log as everything else, with the IP address and the timestamp attached, so a stranger trying the door leaves a trail you can point at.

What happens to my data if I cancel?

Nothing disappears the day you leave. Account data is retained for 90 days so the account can be recovered, and you can export contacts, conversations and pipeline on your way out. Ask for deletion at any point and it is processed within 30 days, apart from anything a law obliges us to keep. Email jesse@jtek.pro and a person handles it.

Is this enough for my broker's compliance review?

A review usually comes down to three questions: is the data encrypted, who can see it, and can you prove what happened. TLS 1.3 in transit and AES-256 at rest answer the first. Role-based access answers the second. An exportable audit log with user attribution answers the third. GDPR and CCPA rights requests, including access, correction, deletion and portability, go to the same address and are answered within five business days.

Security you can trust. Simplicity you'll love.