generated: '2026-08-14' method: searched source: https://www.jeeva.ai/security note: >- Compliance posture is published on Jeeva AI's own security practices page and mirrored in a Vanta-hosted trust center at trust.jeeva.ai. The API/protocol standards below are all recorded as not conforming for the same reason: Jeeva AI publishes no public API, so there is no contract in which OAuth 2.0, OpenID Connect, RFC 9457 problem details, pagination or idempotency semantics could be asserted. Absence here is a measurement of the public surface, not a judgement about the internal platform. standards: - id: soc2 conforms: true evidence: >- "We comply with SOC 2 and GDPR standards... Accredited third-party firms regularly audit our compliance efforts." — https://www.jeeva.ai/security (last updated 2025-05-23); SOC 2 also named as an Enterprise-tier feature on the pricing page. type_reported: null note: The published claim does not distinguish SOC 2 Type I from Type II. - id: gdpr conforms: true evidence: >- Security practices page states GDPR compliance and support for Data Subject Access Requests (DSARs); a Data Processing Addendum and a sub-processor register are published at https://www.jeeva.ai/jeeva-ai-company-dpa and https://www.jeeva.ai/sub-processors. - id: uk-eea-cross-border-transfer conforms: true evidence: >- A UK/EEA Cross-Border Transfer Procedure is named in the enterprise-ready policy set at https://www.jeeva.ai/enterpriseready/global-privacy-compliance-cross-border-data-stewardship - id: iso27001 conforms: false evidence: >- Not claimed by Jeeva AI. ISO 27001 appears only as an attestation Jeeva requires FROM its own high-risk vendors. - id: hipaa conforms: false evidence: Not claimed on any published page. - id: pci-dss conforms: false evidence: Not claimed on any published page. - id: fedramp conforms: false evidence: Not claimed on any published page. - id: oauth2 conforms: false evidence: >- No public API and no published OAuth authorization server; /.well-known/oauth- authorization-server returns 404 on www.jeeva.ai and 403 on api.jeeva.ai. Jeeva acts as an OAuth CLIENT to Google and Microsoft for mailbox and calendar connection, which is not a conformance claim about a Jeeva-published API. - id: oidc conforms: false evidence: >- /.well-known/openid-configuration returns 404. SAML/SSO is sold as an Enterprise feature but no discovery document is published. - id: rfc9457-problem-details conforms: false evidence: No public API contract exists to carry application/problem+json responses. - id: pagination conforms: false evidence: No public API contract. - id: idempotency conforms: false evidence: No public API contract. certifications_published: - SOC 2 - GDPR trust_center: https://trust.jeeva.ai x-evidence: - fetched: '2026-08-14' url: https://www.jeeva.ai/security http_status: 200 - fetched: '2026-08-14' url: https://trust.jeeva.ai/ http_status: 200 - fetched: '2026-08-14' url: https://www.jeeva.ai/.well-known/openid-configuration http_status: 404