Skip to main content

What are Jolly's security and data privacy practices?

An overview of Jolly's encryption, access controls, compliance certifications, and data residency practices.

For: Owners

Encryption

  • In transit: All data is encrypted using TLS 1.2 or higher

  • At rest: Employee data, transaction records, and org data are encrypted using AES-256

Access controls

  • Role-based access control (RBAC) - admins only see what their role allows

  • All admin activity is logged for audit purposes

  • Jolly employees access customer data on a need-to-know basis only

Compliance

  • SOC 2 Type II certified, audited annually

  • Designed to support GDPR, CCPA, and other data privacy regulations

  • Data Processing Agreements (DPAs) available on request - contact your account manager

Data residency

Jolly hosts customer data in the United States. Organizations with specific residency requirements should contact their account manager.

Vulnerability management

Regular penetration testing and vulnerability assessments. Critical patches deployed as needed.

Security documentation

To request Jolly's security overview, SOC 2 report, or a completed security questionnaire, contact your account manager. Available under NDA for enterprise clients.

Questions? Click Help in the left sidebar to start a chat with us. You can also email support@jolly.com (Mon-Fri, 9am-5pm ET; after-hours messages answered next business day).

Did this answer your question?