Redact-It-PRO Trust Center
Security information for clinical document redaction reviews.
This page provides the public Redact-It-PRO security overview. Security, privacy, procurement, and customer IT reviewers can request gated evidence through the form.
- Public overview of hosting, data flow, encryption, access, SDLC, and operations
- Gated evidence package for questionnaires, architecture detail, and policy summaries
- Conservative assurance wording: no unsupported SOC 2, ISO 27001, HIPAA, or FedRAMP claims
Request gated evidence
Use a work email address so we can route the request and send an expiring magic link.
Public Status
Current trust-center status
Redact-It-PRO security content is maintained by JAKITO LLC for customer security reviews. Public content is intentionally concise; sensitive architecture and evidence materials are distributed through the gated workflow.
JAKITO LLC Security Officer
August 3, 2026
Quarterly and after material security, architecture, or vendor changes
No SOC 2, ISO 27001, HIPAA, FedRAMP, or penetration-test completion claim is made on this page.
Security Overview
Minimum viable trust-center summary
Hosting and data flow
The production application uses a static web frontend, a REST-first backend API, managed PostgreSQL, Redis-backed job queues, and private object storage for document artifacts.
Data handling
Source PDFs, extracted text, analysis artifacts, review decisions, and redacted outputs are handled through API-owned workflows and private storage paths.
Access and permissions
Authentication, customer boundaries, project membership, roles, groups, and team assignments control administrative, reviewer, and export workflows.
Encryption and secrets
TLS is required for browser and API traffic. Production secrets are stored outside the repository, and private object storage is provisioned with encryption at rest.
SDLC and validation
Development uses a small-team Agile workflow with backlog tracking, code review, automated backend tests, frontend production builds, and deployment smoke checks.
Operations and incident response
Operational controls include request IDs, health checks, job status tracking, backups, recovery planning, and a security reporting path through security@jakitollc.com.
Gated Package
Evidence available after request
Approved reviewers may receive access to the gated trust-center page and supporting artifacts appropriate to the review purpose, customer relationship, and required confidentiality level.
Questionnaire responses, policy summaries, control-to-evidence mapping, and current status notes.
Hosting model, technical architecture, data-flow detail, and customer responsibility boundaries.
Independent assessment summaries are shared only when current evidence exists and has been approved.
Security Contact