Security

How Jedru protects your account, your data and our software

Written for IT managers who need to approve a vendor. If you need a filled security questionnaire, email security@jedru.com.

1

Single sign-on across products

Your Jedru account is an OpenID Connect identity. Vortex, iMonitor and Craft Studio accept tokens only from it, so a cancelled subscription or removed user loses access everywhere within minutes.

2

One active session per user

A second sign-in ends the first after a prompt. Organisations can also require an authenticator-app code and restrict sign-in to their office IP range.

3

Trusted devices

New browsers and PCs are fingerprinted and confirmed by a one-time email code. Administrators can see and revoke every device from the portal.

4

Signed entitlements

Each seat is an Ed25519-signed entitlement issued by the portal and verified by the product on every request. Keys cannot be edited, extended or forged; the private key never leaves our servers.

5

Server-side code

Web products render on our servers; browsers receive screens, not application code. The iMonitor agent is code-signed, obfuscated and bound to the hardware fingerprint of the PC it was activated on.

6

Data

Encrypted in transit (TLS 1.2+) and at rest. Daily backups retained 30 days. Each organisation's data is logically isolated; exports are available on request and deleted 30 days after an account closes.

7

Payments

Card details never touch Jedru systems. Payments are processed by PayHere (PCI DSS Level 1, 3-D Secure). We store only the last four digits and the payment reference.

8

Self-hosted option

Enterprise customers can run products inside their own network with an offline, machine-bound licence file. Contact sales for details.