Security
Jive is built for auditable scope observability with least-privilege access.
What we store
- Scope configuration (scopes, relationships, criteria, and dependencies)
- Claimed state from connected systems (metadata only)
- Normalized evidence observations (metadata only)
- Integrity evaluations, drift records, and audit events
What we do not store
- Source code contents
- Raw artifacts beyond metadata needed for evaluation
- Source artifacts stay in systems of record
- Credentials beyond tokens required to access integrations
Retention
Retention is plan-based and configurable by organization:
- Free: 7 days
- Pro: 365 days
- Enterprise: unlimited
Access controls
Access is scoped to organizations with role-based permissions (Owner/Admin/Member). Least-privilege defaults keep visibility and actions constrained to the organization boundary.
Audit and retention
Audit logs capture configuration changes, integrity evaluations, drift detection, and enforcement decisions. Exports (CSV or API) are available on Pro and above.
Enterprise options
Enterprise plans support SSO (SAML/OIDC), SCIM, security reviews, and SLAs.