Security Policy

Last updated: October 11, 2026
This Security Policy describes how ProfitJam, LLC (“ProfitJam,” “we,” “us” or “our”) protects information handled through the ProfitJam platform. It is intended to help customers understand our safeguards and assess whether the service meets their needs.
This policy should be read with our Privacy Policy, Data Retention Policy and Terms & Conditions. Additional commitments may be set out in a written customer agreement. Applicable law takes priority over this policy and any agreement.

1. Scope and appropriate use

ProfitJam provides tools for websites, marketing content, customer communications and related business activities. The service handles information such as account details, business profiles, marketing materials and customer or prospect contact information.
The standard service is not intended to store medical records, Social Security numbers, identity documents, tax returns, investment account records or other confidential financial records. Customers must not request or upload this information through forms, media, content or AI features. Payment details should be entered only through the designated payment service.
Customers are responsible for collecting only the information they need, giving appropriate notices, obtaining required permissions and configuring their forms and connected services accordingly.

2. Hosting and data location

Our primary production systems use Amazon Web Services in the United States. Public websites and media may be delivered through a global content delivery network. Connected services and other service providers may process information in additional locations.
A service provider’s security certifications apply to that provider’s services. They do not mean that ProfitJam itself holds the same certifications. Customers with data-location requirements should agree those requirements with us before providing the relevant information.

3. Encryption and connected accounts

  • We use HTTPS to protect information sent between users and the ProfitJam application.
  • Production database and object storage use encryption at rest, and database connections use encrypted transport.
  • Credentials stored for supported connected accounts are encrypted and used to provide the connection’s requested functions.
  • Payment card information is handled through our payment provider. ProfitJam does not store full payment card numbers.
These safeguards are not end-to-end encryption. ProfitJam and its service providers must be able to process information to operate the features you use. Do not place passwords, private keys or other access credentials in ordinary content, form responses or AI prompts; use the designated connection settings.

4. Account and workspace access

We use account authentication, workspace membership and permission checks to restrict access to customer information. Workspace owners and administrators control their team’s membership and available permissions.
Access by ProfitJam personnel is limited to work needed to operate, support and protect the service. Customers should use individual accounts, protect their sign-in details, remove access when a team member leaves and use available additional sign-in protections. Contact us about multi-factor authentication requirements before relying on a particular configuration.

5. Public content and uploaded media

Published websites, content and associated media are public by design. Uploaded media may be accessible to anyone who has its address, even when it has not been placed on a published page. An unpublished item or an unshared address should not be treated as confidential storage.
Customers must not upload material that requires restricted document access. Removing content from ProfitJam cannot recall copies that other people have already downloaded, or copies held independently by search engines, social networks or other services.

6. Software maintenance and security review

Our development process includes code review, automated checks and software dependency updates. We review reported weaknesses and prioritize corrective work based on severity, potential exposure and the systems affected.
Security review is an ongoing activity. No website, software platform or transmission method can be guaranteed to be free from every weakness or interruption.

7. Service providers and AI features

We use service providers for functions such as hosting, sign-in, payment processing, email delivery, operational monitoring and AI-assisted features. Customers may also connect services of their own.
Information supplied to an enabled feature may be sent to the providers needed to perform that feature. This can include prompts, business context, content and other information selected for processing. Do not submit sensitive information outside the permitted scope of the service.
Our Privacy Policy describes how personal information is handled. Customer agreements and any applicable data processing terms address additional obligations. Connecting another service does not transfer responsibility for that service’s account settings or independent data practices to ProfitJam.

8. Backups, recovery and retention

We maintain database backups to support recovery from service failures and operational errors. Access to backup storage is restricted. Backup retention and deletion are addressed in our Data Retention Policy.
Recovery backups are not a customer records archive. A backup does not guarantee that a particular deleted item or historical version can be restored. Any agreed availability, recovery or long-term retention commitment must be stated in the applicable customer agreement.

9. Security incidents and notification

We maintain an incident response process for assessing suspected incidents, limiting their effects, investigating what happened and coordinating recovery.
When we become aware of a personal-data breach affecting customer information, we notify affected customers without undue delay and within applicable legal and contractual deadlines. An initial notice may be followed by updates as more information becomes available; we do not delay a required notice until every part of an investigation is complete.
Where applicable, notices describe the information and services affected, the known timing and consequences, the measures taken or proposed and actions the customer should consider. Customers remain responsible for their own notifications and regulatory obligations, with our assistance where required.
Report a suspected security incident to security@profitjam.io. If that address is unavailable, contact support@profitjam.io. Include enough information for us to investigate, but do not send passwords or sensitive customer records by ordinary email.

10. Regulated businesses and assurance

Customers in regulated industries remain responsible for deciding whether the service, its configuration and their operating procedures meet their obligations. Special requirements for records, approval workflows, exports or incident notices must be agreed in writing before the customer relies on them.
ProfitJam does not currently hold SOC 2 or ISO 27001 certification. Use of the platform does not, by itself, establish compliance with financial-services or privacy requirements. The standard service is not offered for storing protected health information under HIPAA.
Customers assessing ProfitJam may request our customer-facing security information and due-diligence materials. Detailed internal procedures and security findings may be shared only under appropriate confidentiality arrangements.

11. Changes and contact

We may update this policy as the service, our practices or applicable requirements change. The date above identifies the latest revision. We provide additional notice where required by law or our agreement with you.
For security questions, contact security@profitjam.io. For personal-information requests, use the contact details and request process in our Privacy Policy.