Redact-It-PRO Trust Center

Security information for clinical document redaction reviews.

This page provides the public Redact-It-PRO security overview. Security, privacy, procurement, and customer IT reviewers can request gated evidence through the form.

  • Public overview of hosting, data flow, encryption, access, SDLC, and operations
  • Gated evidence package for questionnaires, architecture detail, and policy summaries
  • Conservative assurance wording: no unsupported SOC 2, ISO 27001, HIPAA, or FedRAMP claims

Request gated evidence

Use a work email address so we can route the request and send an expiring magic link.

Magic links expire automatically.

Public Status

Current trust-center status

Redact-It-PRO security content is maintained by JAKITO LLC for customer security reviews. Public content is intentionally concise; sensitive architecture and evidence materials are distributed through the gated workflow.

Owner

JAKITO LLC Security Officer

Last Reviewed

August 3, 2026

Review Cadence

Quarterly and after material security, architecture, or vendor changes

Assurance

No SOC 2, ISO 27001, HIPAA, FedRAMP, or penetration-test completion claim is made on this page.

Security Overview

Minimum viable trust-center summary

Hosting and data flow

The production application uses a static web frontend, a REST-first backend API, managed PostgreSQL, Redis-backed job queues, and private object storage for document artifacts.

Data handling

Source PDFs, extracted text, analysis artifacts, review decisions, and redacted outputs are handled through API-owned workflows and private storage paths.

Access and permissions

Authentication, customer boundaries, project membership, roles, groups, and team assignments control administrative, reviewer, and export workflows.

Encryption and secrets

TLS is required for browser and API traffic. Production secrets are stored outside the repository, and private object storage is provisioned with encryption at rest.

SDLC and validation

Development uses a small-team Agile workflow with backlog tracking, code review, automated backend tests, frontend production builds, and deployment smoke checks.

Operations and incident response

Operational controls include request IDs, health checks, job status tracking, backups, recovery planning, and a security reporting path through security@jakitollc.com.

Gated Package

Evidence available after request

Approved reviewers may receive access to the gated trust-center page and supporting artifacts appropriate to the review purpose, customer relationship, and required confidentiality level.

Security review

Questionnaire responses, policy summaries, control-to-evidence mapping, and current status notes.

Architecture

Hosting model, technical architecture, data-flow detail, and customer responsibility boundaries.

Assurance

Independent assessment summaries are shared only when current evidence exists and has been approved.

Security Contact

Report a vulnerability or request follow-up

Send security reports and trust-center follow-up requests to security@jakitollc.com. Please include the affected URL or component, reproduction steps, potential impact, and your contact information. Do not access, modify, delete, or share customer data that is not yours.