Security

How we protect your data and payments

Security isn’t a launch checkbox for a staffing marketplace — it’s the product. Here’s how JUMP handles payments and data.

Card data never touches our servers

Payments are processed by Stripe. Card numbers are entered directly into Stripe’s systems, so JUMP never stores or transmits them — the SAQ-A model.

Encrypted in transit and at rest

All traffic is served over HTTPS/TLS, and data is encrypted at rest in our cloud infrastructure.

Least-privilege access

Access to production data is restricted, authenticated, and scoped to what a role needs to do its job.

Payments & PCI

JUMP uses Stripe to process all employer payments. Because card details are captured directly by Stripe and never pass through or rest on JUMP’s servers, JUMP falls under the simplest PCI scope (SAQ-A). Stripe is a PCI-DSS Level 1 certified service provider.

Data protection

Traffic between your device and JUMP is encrypted with TLS. Data is encrypted at rest in our cloud infrastructure. Access to production systems is limited to authorized personnel, authenticated, and scoped by role.

Responsible disclosure

If you believe you’ve found a security vulnerability, please email support@jumpco.co with the details. We welcome good-faith reports and will respond as quickly as we can.

A note on scope

JUMP is in early access, and our formal security and compliance program is being built out alongside the product. This page describes our current practices in plain language; it is not a certification or an audit report. For specific security or compliance documentation, contact us at support@jumpco.co.

Have a security or compliance question?

Email us and we’ll get you the detail you need.