Data Protection and Privacy
Where is my data hosted?
Your data is hosted in state-of-the-art secure cloud environments, including Amazon Web Services (AWS) and trusted SaaS platforms such as Google Workspace.
How is my data protected?
JustFund uses industry-standard encryption methods, including TLS 1.2 for data in transit and AES-256 for data at rest, along with role-based access controls and security monitoring.
How often is data backed up?
JustFund data is backed up daily in accordance with our business continuity and recovery procedures.
How long do you retain my data, and can I request deletion?
Data handling follows JustFund’s Data Classification and Privacy Policies. Users may request changes or deletion of their data, in accordance with privacy standards such as the GDPR and CCPA.
Can I request an export of our data?
Yes, this process is documented in our Privacy Terms.
Access and Controls
Who has access to my data?
Access is limited through role-based access controls to authorized personnel and service providers with a legitimate business need.
Do you control and monitor employee access?
Yes. Access controls are reviewed regularly.
Employee Training and Awareness
Are employees trained on security?
Yes. Employees receive security training upon hire and annually thereafter.
How are you prepared for phishing or social engineering?
Employees receive monthly phishing awareness training. Annual disaster recovery simulations, such as Tabletop exercises, are scheduled to model attacks and test responses. Contractors are included in training programs.
System and Application Security
Do you conduct security testing?
Yes. JustFund performs periodic risk assessments, vulnerability scanning, penetration testing, and ongoing security monitoring.
How do you manage vendors?
Vendors are reviewed through a Third-Party Risk Management program, with controls to ensure they meet JustFund’s security standards.
Incident Response and Recovery
What happens if there is a data breach?
JustFund maintains procedures to identify, assess, and respond to security incidents. If a breach involving personal data occurs, affected parties will be notified as required by applicable law.
How quickly can you recover from outages?
Business Continuity Planning and backup testing ensure the timely restoration of systems. Security maintenance includes semiannual reviews of recovery readiness. JustFund’s Recovery Time Objective (RTO) is 8 hours, and Recovery Point Objective (RPO) is 24 hours.
General Trust and Transparency
Who oversees security?
The Chief Information Security Officer (CISO) leads security, supported by the JustFund Security Committee (JSC). Both report regularly to the Executive Committee.
How often do you update policies?
All security policies are reviewed at least annually and updated as necessary to address new risks.