← Back to sign in
JRC Tellus
A product of JRC

Security & Trust

How JRC Tellus protects your organisation's confidential ESG and people data.

Version 1.2 · Effective 20 June 2026 · Updated 22 July 2026 · Summary only, the binding commitments are in our Data Processing Agreement and Privacy Policy.

JRC Tellus is operated by Joshua Rayan Communications (JRC). Companies use it to record confidential sustainability data, energy and emissions figures, financial inputs, the names and roles of their people, and supporting evidence. We treat that data as our customers' property and protect it with the controls below. This page is a plain-language summary; where it touches a legal obligation, the Data Processing Agreement governs.

Where your data lives

Your data's primary store is in Singapore. We use a small number of established sub-processors, each under a written data-protection contract:

ProviderRoleLocation
Supabase (on AWS)Database, authentication and evidence-file storageSingapore: AWS ap-southeast-1
CloudflareApplication hosting, content delivery, and off-site backup of evidence files (Cloudflare R2)Global edge network; evidence backup stored in Asia-Pacific
ResendTransactional email (invitations, password resets, reminders), email addresses and message content onlyTokyo, Japan
StripePayment processing for self-serve JRC Tellus SME subscriptions. Stripe receives your billing name, email and payment details directly: JRC Tellus never receives or stores card numbers. Applies only to self-serve subscribers.Processed outside Malaysia under Stripe's own standard contractual clauses
Cloudflare TurnstileBot protection on the public sign-up form. Sees the visitor's IP address and browser signals at sign-up only; no account data.Global edge network

We notify client administrators in advance of any change to this list, giving you the opportunity to object on reasonable data-protection grounds.

Encryption

Access control & tenant isolation

Integrity & the assurance record

Availability & recovery

JRC Tellus runs on managed cloud infrastructure. The database is backed up daily with point-in-time recovery. Evidence files are held in managed, redundant object storage and are additionally copied daily to independent off-site backup storage with a different provider, so they can be recovered even in the unlikely event of a problem at our primary store. When evidence is deleted in the Platform, its off-site backup copy is purged within 30 days. We periodically test our ability to restore so that we can recover availability in the event of an incident.

If something goes wrong

If we become aware of a personal-data breach affecting your data, we will notify you without undue delay and within 72 hours, with the information you need to meet your own regulatory obligations under the Malaysian PDPA and, where applicable, the GDPR. Report a suspected security issue to tom@jr.com.my.

Your data is yours

What we don't yet claim

We're an early-stage product backed by a specialist consultancy, and we believe in being precise. We do not currently hold a formal certification such as SOC 2 or ISO 27001. The controls above are real and in force; we're happy to walk your IT or procurement team through them and to complete a security questionnaire on request.