# 9jatesters Security & DPA Summary

Updated: 2026-09-12

This is a procurement summary, not a SOC 2 report or ISO certificate. 9jatesters can sign a DPA for scoped commercial work; certification audits are not complete yet.

## Current Controls

- Bank-account verification is handled through Flutterwave; 9jatesters stores only a one-way hash for uniqueness.
- Buyer-facing media playback is routed through authenticated API proxies rather than exposing storage URLs in client JSON.
- Contributor-data exports require approved submissions, live ai_data_reuse consent, and provenance rows linked to the exact job.
- Exports omit raw PII: no names, phone numbers, bank details, exact addresses, or raw internal object URLs.
- Admin reviews, consent events, payouts, and material state changes write audit-log records for incident reconstruction.

## Procurement Artifacts

- DPA coverage: Available for scoped paid work. Standard DPA terms cover controller/processor roles, purpose limitation, sub-processor notice, deletion timelines, breach notice, and data subject request handling.
- Processor list: Published. Supabase, Vercel, Cloudflare, Flutterwave, Google Gemini, Resend, Disify, Country.is, Google Safe Browsing, and Stripe for approved manual international billing only.
- Identity-verification explainer: Published. Bank-account verification happens only after demo approval and before paid work unlocks; it is handled by Flutterwave, and only a one-way hash is stored.
- Backup / RPO / RTO: Operator-managed. Backups and incident playbooks are operator-managed and not yet replicated off-site. Larger engagements receive the hosted-production upgrade plan, target PITR posture, RPO/RTO assumptions, and vendor questionnaire responses before launch.
- Incident process: Published summary. Security disclosures go to support@9jatesters.com. Confirmed material incidents are logged internally, affected customers are emailed, and NDPA-relevant breach notices target 72 hours after confirmation.
- Architecture diagram: Public summary. Browser clients talk to the Next.js app; authenticated server routes broker database, storage, email, payment, AI summarisation, and safety checks. Raw private media URLs are not exposed in buyer/tester JSON.

## Data Processing Terms Covered In The DPA

- Roles: client/AI buyer as controller or independent controller depending on the brief; 9jatesters as processor for routed testing work.
- Purpose limitation: tester recordings and AI-data contributions are used only for the scoped brief unless separate AI-data reuse consent/licence exists.
- Sub-processors: Supabase, Vercel, Flutterwave, Google Gemini, Cloudflare, Resend, Disify, Country.is, Google Safe Browsing, and Stripe only for approved manual international billing.
- Retention: session recordings default to deletion after the contractual retention window; custom retention can be set in the signed brief.
- Breach notice: target notice within 72 hours of confirmed breach where NDPA notification duties apply.
- Data subject requests: deletion/access requests via support@9jatesters.com.

## Known Gaps

- No SOC 2 Type II or ISO 27001 certificate yet.
- Public status is available at /status; incident updates are still handled by email until traffic justifies a third-party status vendor.
- Public proof assets are redacted/sample unless a customer gives written permission.
