Security
Last updated on August 17, 2026.
Juno is used by financial advisers, which means it handles some of the most sensitive material its users hold. We take reports of security problems seriously and we would rather hear about a problem from you than from a customer.
Reporting a vulnerability
Email security@thenevercompany.ai. You do not need an existing relationship with us to report something, and you will not be penalised for reporting in good faith.
Where you can, please include:
- What the issue is, and what an attacker could do with it
- The steps needed to reproduce it
- The version of Juno or the URL affected
- How you would like to be credited, if you would like to be credited at all
What we commit to
- We acknowledge your report within two business days.
- We tell you whether we have reproduced the issue, and give you an honest assessment of severity.
- We keep you updated while we work on a fix, rather than going quiet.
- We tell you when it is fixed, and credit you publicly if you want that.
If an issue affects customer data, we notify affected customers promptly and factually — including what we know, what we do not yet know, and what we are doing about it. Our customers carry their own regulatory notification duties, so vagueness on our part creates a problem for them, not only for us.
Safe harbour
If you make a good-faith effort to comply with this policy during your research, we will consider your research authorised, we will work with you to understand and resolve the issue quickly, and we will not pursue or support legal action against you. Good faith means: report promptly, do not access or modify data belonging to anyone else, do not degrade the service for other users, and give us reasonable time to fix the issue before disclosing it publicly.
If legal action is initiated by a third party against you for activity conducted in accordance with this policy, we will make this authorisation known.
Scope
In scope:
- The Juno desktop application
- Juno's AI Cloud and other Juno-operated services
- This website
Out of scope:
- Denial-of-service and volumetric testing
- Social engineering of our people, customers, or vendors
- Physical attacks
- Reports from automated scanners without a demonstrated, exploitable impact
- Vulnerabilities in third-party services we use — please report those to the third party, though we would still like to know
How Juno is built
Some architectural facts that are usually the next question after "how do I report something":
- Your data stays on your device by default. AI processing happens locally unless you deliberately choose a cloud processor.
- Databases on your device are encrypted at rest, with keys derived from a secret you hold. We cannot read your local data.
- The desktop application ships with no third-party API keys. Provider credentials are held server-side and never distributed in a build.
- When you do choose cloud processing, requests are pinned to providers that do not retain, log, or train on your data, and identifying data is scrubbed before it is sent. We do not log your prompts or documents.
Our Privacy Policy describes data handling in full. We do not hold a SOC 2 report and are not currently pursuing one; we would rather be evaluated on what we can show you. If you are performing vendor diligence and need detail beyond this page, write to security@thenevercompany.ai.