SECURITY & COMPLIANCE

Built to be scrutinised

Jurra handles privileged, tiered material under a tribunal’s protective order. The controls were designed against SOC 2 and ISO 27001 from the first commit — not retrofitted — and the system produces the evidence an auditor samples.

Two independent enforcement layers
A policy decision point authorises every action, and Postgres row-level security enforces it again — forced on every table. Neither layer assumes the other is correct.
Protective-order tiers
Confidential, AEO and Source Code are enforced physically: watermarked proxied downloads, client-contact exclusion, and Source Code that never leaves the secure terminal.
Existence is confidential
404-not-403: a matter behind an ethical wall is indistinguishable from one that does not exist. Screened counts are disclosed; identities never are.
Append-only audit
Every access is hash-chained and written in the same transaction as the action, so an unlogged access cannot occur. Retained seven years to a WORM archive.
Contained AI
Retrieval is filtered before the model sees anything; passages are wrapped as data against injection; every citation is verified against the record.
Detections
Twelve detections run hourly in the database over the audit log — bulk download, wall probing, impossible travel, configuration drift — each alerting a human, not a retry.
document.download
A. Okonjo
ai.retrieve
P. Nair
document.read · REFUSED
T. Ferreira
hash-chained · append-only

Formal SOC 2 Type II and ISO 27001 certification is a defined programme item and is pursued on its own timeline; this page describes the controls the product enforces today.

Sign in