Security and privacy

Trust controls for customer conversations from the start.

Jiffy handles customer messages, AI traces, and business rules as sensitive workspace data. The v1 product stays focused and blocks high-risk advice.

Tenant isolation

Every conversation, rule, usage event, assistant version, and audit entry belongs to one workspace.

GDPR-first controls

Export, deletion, retention windows, privacy copy, and human correction are planned from day one.

No regulated advice in v1

Medical, legal, financial, and high-risk advice are blocked until review workflows exist.

Auditable AI

Admins see the rule version, source context, tool trace, and corrections behind each answer.

Admin visibility

Every correction becomes a versioned decision.

Admins should be able to see what the assistant knew, which rules were active, how it answered, and what changed after a correction.

AI/tool trace visible in every conversation.
Published assistant versions before live use.
Export and deletion controls in each workspace.
Human takeover pauses AI on the conversation.
Funnel and billing events tracked separately.
No cross-tenant access, including setup sessions.