For: Owners
Encryption
In transit: All data is encrypted using TLS 1.2 or higher
At rest: Employee data, transaction records, and org data are encrypted using AES-256
Access controls
Role-based access control (RBAC) - admins only see what their role allows
All admin activity is logged for audit purposes
Jolly employees access customer data on a need-to-know basis only
Compliance
SOC 2 Type II certified, audited annually
Designed to support GDPR, CCPA, and other data privacy regulations
Data Processing Agreements (DPAs) available on request - contact your account manager
Data residency
Jolly hosts customer data in the United States. Organizations with specific residency requirements should contact their account manager.
Vulnerability management
Regular penetration testing and vulnerability assessments. Critical patches deployed as needed.
Security documentation
To request Jolly's security overview, SOC 2 report, or a completed security questionnaire, contact your account manager. Available under NDA for enterprise clients.
Questions? Click Help in the left sidebar to start a chat with us. You can also email support@jolly.com (Mon-Fri, 9am-5pm ET; after-hours messages answered next business day).
