Security FAQ / Questionnaire
This document provides answers to common questions from customer procurement and security assessment teams regarding SaaSJet’s governance, employee awareness, access control, audit practices, and compliance.
1. Security Governance & Policies
2. Employee Awareness & Training
Yes. All vendor employees undergo mandatory security awareness training at least once per year, and in practice 1–2 times annually depending on role and responsibilities.
Yes, access to client data is granted only to employees or contractors who require it for legitimate business purposes and is governed by strict security controls.
Access is provided based on the principle of least privilege, meaning individuals are granted the minimum level of access necessary to perform their job functions. Access rights are regularly reviewed and promptly revoked when no longer required.
Yes. All employees and contractors with system access undergo background checks, including criminal background screening, in compliance with local regulations.
3. Access Control & Identity Management
Yes. Access is managed through Jira’s native roles, groups, and permission schemes, which our apps inherit and enforce.
4. Audit & Monitoring
5. Data Handling, Architecture & Residency
6. Compliance & External Validation
Yes. We are audited by an independent third party and have achieved SOC 2 Type II compliance.
We have implemented security and privacy controls aligned with GDPR principles and are actively working toward full GDPR compliance. Our data protection practices are supported by SOC 2 Type II – compliant controls.
7. Support, Service Levels
If you don’t find the answer you’re looking for or would like more details, please contact us at support@saasjet.com or via SaaSJet’s Support Portal.