Security
Security at Joby.
We use layered safeguards to protect customer data and reduce risk, including encryption, access controls, tenant isolation, and operational monitoring.
No cloud service can guarantee absolute security. Our goal is to implement reasonable safeguards, respond quickly, and continuously improve.
Encryption and transport security
We use encryption in transit (TLS) and rely on managed infrastructure and vendors that support encryption at rest for stored data. Passwords are stored using one-way hashing; we do not store plaintext passwords.
Access control and least privilege
Role-based access controls limit access by organization and user role (for example admin, agent, and subcontractor). Customer admins are responsible for granting and reviewing user access inside their workspace.
Tenant isolation
Joby is a multi-tenant platform with logical data isolation controls at the application and database layers. We design features and access paths to restrict users to their own organization's data.
Logging and monitoring
We log important authentication, administrative, and operational events to support troubleshooting, auditing, and incident response. Log availability and retention may vary by plan and environment.
Incident response
If we detect or confirm a security incident, we investigate, contain, and remediate based on severity. We provide notice of qualifying incidents as required by law and our contractual commitments.
Security program maturity
We continuously improve our security controls, documentation, and vendor management. Joby is not currently certified under any third-party security framework. We will update this page if and when that changes.
Data ownership and retention controls
Customers own their Customer Data. Export and retention options are provided within the product or support workflows, subject to subscription terms, backup cycles, and legal obligations.
Responsible disclosure
We welcome responsible security reports. Please do not access customer data, disrupt service, or conduct destructive testing. Contact support@joby.io with details so we can triage quickly.
Shared responsibility
Joby secures the platform and core infrastructure within our control. Customers are responsible for user access, device security, lawful communications consent, and internal handling of exported data.
Report a security issue
Email support@joby.io with a clear description, affected URL or screen, reproduction steps, and any proof-of-concept. Please avoid sending sensitive customer data unless specifically requested through a secure channel.
This is not a bug bounty program unless we state otherwise in writing.
Questions about security?
Contact our team for security questions, vendor documentation requests, or to discuss your specific requirements.
Contact us