Jade powered by mci group
Home Legal Center Log in

Legal Documents

Terms of Use Privacy Policy AI Use & Transparency Acceptable Use Data Processing Addendum Security & Trust Cookie Policy Government Use GDPR Addendum

Security & Trust Statement

Jade Event Operating Platform|Last Updated: June 25, 2026

This Security & Trust Statement provides a high-level overview of security practices for Jade. It is for informational purposes and does not modify any contract.

1. Hosting and Data Residency

Jade is hosted in the United States using reputable cloud and managed-service providers. Customer-specific data residency commitments, if any, are governed by the applicable written agreement.

2. Security Program Overview

MCI maintains an information security program designed to protect confidentiality, integrity, and availability of systems and data.

3. Core Controls (High-Level)

  • Encryption: Data encrypted in transit using TLS; encryption at rest for supported systems.
  • Access Controls: Role-based access, tenant/client/event scoping, least privilege, and administrative access controls.
  • API Controls: Bearer-token API accounts, token hashing, optional expiry, scoped event/client grants, PII redaction, and per-account rate limits.
  • Integration Controls: HMAC-signed outbound webhooks, encrypted webhook secrets, idempotent inbound payment/email/e-signature callbacks, and participant-agent OTP sessions.
  • Monitoring & Logging: Structured logging, correlation identifiers, health checks, API usage metrics, monitoring, and alerting for suspicious activity.
  • Vulnerability Management: Patch management, vulnerability scanning, and remediation practices.
  • Secure SDLC: Secure development practices, code review, and change management.
  • Incident Response: Documented incident response plan and breach notification procedures.
  • Backups & Resilience: Backup routines and disaster recovery considerations appropriate to risk.
  • Vendor Management: Due diligence and contractual controls for critical vendors/subprocessors.

4. Payments

Payments are processed through Payment Processors such as Stripe. Card guarantees may be tokenized through a third-party vault such as Basis Theory where configured. Jade does not store full payment card numbers.

5. Customer Responsibilities

Customers should use strong authentication, limit user access, and configure event workflows responsibly, including controls over AI-enabled automation where applicable.

6. Contact

Security questions: legal@wearemci.com (or your designated support contact under contract).

Jade powered by mci groupJade by MCI USA Operating Co.
HomeLegalPrivacyTermsContact