Jabr security
Clear safeguards for your books.
From team access to journal review, we explain Jabr's own controls and the scope of our cloud provider's certifications.
Last reviewed: 25 September 2026
Cloud hosting
Jabr is hosted on cloud services covered by security and privacy certifications
These are the hosting provider's certifications, not independent Jabr certifications.
Certification and report scopeJabr controls
Practical protection where it matters.
Data and Access Protection
- HTTPS/TLS in transit and Google Cloud platform-managed encryption at rest.
- Company-scoped access rules, user roles, and scoped application and token permissions.
- Encryption of sensitive integration and signing secrets before storage according to their path.
- Audit paths for supported administrative, support, and sensitive-change events.
Account and Application
- Firebase authentication, email verification, session expiry and revocation, rate limits, and abuse controls.
- Server-side membership and authorization checks for accounting operations and integration paths.
- Central release controls prevent unauthorized integration connection or synchronization; security does not rely on hiding a browser card.
AI and Integration Safety
- Server-enforced user approval is required before a proposed journal entry from chat or MCP can be posted.
- Sensitive operations require additional confirmation; tokens are company- and scope-bound and revocable.
- Transfers to AI services and external connectors remain subject to disclosure, granted scopes, and the Privacy Policy.
Cloud hosting
Official provider certification sources
Jabr runs on Google Cloud services covered by Google Cloud's information security management system certifications to ISO/IEC 27001, ISO/IEC 27017, and ISO/IEC 27018. The listed services include Cloud Run, Firestore, and Cloud Storage.
Google Cloud also issues SOC 2 Type II audit reports for covered services. These certifications and reports belong to Google Cloud as the infrastructure provider; they do not certify Jabr itself or constitute a separate SOC 2 report for Jabr.
Review each certification and report at the official source. Covered services may change with the provider's current documentation.
Continuity and reporting
Continuity and Incidents
Jabr operates backup, recovery, and incident-response controls according to the actual environment configuration and operating plan. This page does not promise a specific backup schedule, retention window, or recovery objective unless stated in a separate service agreement. Regulatory and data-subject notification is assessed against statutory harm thresholds and deadlines.
User Responsibility and Reporting
Users must protect devices, credentials, and tokens, review roles and connected applications, and revoke access no longer needed. Report vulnerabilities to info@jabrhq.com.
Official legal references
This page describes Jabr's security controls in practical terms without an absolute guarantee or an unstated security certification.