Security · founding pilot
Use a controlled preview, not customer production data.
A browser test can see whatever the test account can see. We scope pilots around that fact instead of hiding it in fine print.
Scope controls
- We test only a target you own or are explicitly authorized to test.
- Founding pilots use preview or staging environments and synthetic test data.
- Submitting the public form never launches a browser run.
- Passwords, cookies, tokens and signed URLs must not be entered in the public form. If access is needed, we arrange it separately.
- Destructive payments, live customer records and broad production scans are excluded from the founding offer.
Data flow
During a scoped run, page text and screenshots may be processed by the model provider named in the pilot scope. Screenshots cannot be reliably redacted after capture, which is why test data and least-privilege accounts are required. We do not use customer content, screenshots or journeys to train or benchmark JinuGen without written opt-in.
Retention
Our default is to delete raw screenshots, video and browser traces within 14 days after delivery, and the delivered redacted report within 30 days. Pilot intake records are retained for up to 90 days unless an active customer relationship or legal obligation requires longer. A customer may request earlier deletion.
Operational safeguards
- Private request data is stored server-side behind Supabase row-level security with no anonymous policies.
- Public intake is bounded, same-origin checked, honeypot protected and rate-limit ready.
- Operational logs exclude submitted email addresses, target URLs and journey text.
- Reports distinguish a compromised run from a product finding.
Report a security issue
Please email security@jinugen.com with a concise description and reproduction details. Do not include live credentials or customer data.