Home/Security

Security Architecture

JuiceFactory was designed security-first from the infrastructure layer up. Every architectural decision — from datacenter placement to memory management — is driven by a single constraint: customer data must never be exposed, persisted, or accessible beyond the scope of a single inference request.

Infrastructure

EU-only compute

All inference runs on hardware owned and operated by Juice Factory in a colocation facility in Solna, Sweden. No request is routed outside the EU/EEA. The facility operator is an EU-incorporated entity subject to Swedish and EU law and has no logical access to systems or data.

No US sub-processors

JuiceFactory does not use US-headquartered cloud providers for inference, storage, or networking. This eliminates exposure to CLOUD Act and FISA 702 compelled-disclosure risks.

Single-tenant hardware

The hardware is owned and operated by Juice Factory and is not shared with any other cloud tenant. Requests are segregated logically by API key and project; each request is scheduled and generated independently and its state is released when the response completes.

Zero-Retention Architecture

This applies to the public API. Prompts and completions sent to the API are processed entirely in memory. They are not written to disk, not logged to a persistent store, and not retained after the HTTP response completes. There is no abuse-monitoring log, no training pipeline, and no deferred batch queue that touches your data. The optional portal chat is a separate feature: it stores conversations as a product function, encrypted at rest, and is described in the DPA.

Request lifecycle

1
TLS termination
Request arrives over HTTPS. Payload decrypted at edge.
2
In-memory inference
Prompt loaded into GPU VRAM. Model generates response. No disk I/O.
3
Response delivered
Completion streamed to client. Memory freed immediately.
4
Zero residue
No prompt or completion persisted. Operational metadata only.

Operational metadata is retained for authentication, security, operation, metering and invoicing — including the model invoked, a request identifier, message and token counts, duration and HTTP status. The prompt and completion are never part of that record. The full field list and retention periods are in the DPA.

Compliance

GDPR

GDPR Article 28 compliant processor

JuiceFactory acts as a data processor under GDPR. A signed Data Processing Agreement (DPA) is available to all customers and covers data handling obligations, sub-processor disclosure, breach notification timelines, and data subject rights support. The DPA is available for download at portal.juicefactory.ai.

SOC 2

SOC 2 Type II audit in progress

SOC 2 Type II audit engagement is underway with an expected completion date in Q3 2026. The audit covers the Security and Confidentiality trust service criteria. Report will be available under NDA upon completion.

ISO

ISO 27001 certification planned

ISO 27001 certification is on the roadmap following SOC 2 completion. The information security management system (ISMS) is already aligned with ISO 27001 Annex A controls as part of the SOC 2 preparation.

Sub-processors

Under GDPR Article 28(2), we disclose all sub-processors involved in handling customer data. JuiceFactory operates its own inference infrastructure. No third-party AI provider processes your prompts or completions.

Sub-processorPurposeLocationData access
AB Juice Factory AIAI inference, API gateway, billingSolna, SwedenAPI content in memory only; operational metadata retained
BunnyWay d.o.o.Content delivery, edge protection, TLS terminationEU points of presence; origin shield in FranceTransport only; bodies not logged, client IP anonymised
Datacenter operatorPhysical hosting, power, networkSolna, SwedenNo logical access to data

No US-headquartered entity appears in the sub-processor chain. The full sub-processor list with legal entity names is included in the DPA.

Responsible Disclosure

If you discover a security vulnerability in JuiceFactory's infrastructure or API, please report it responsibly. We ask that you:

  • Do not publicly disclose the vulnerability before we have addressed it
  • Provide sufficient detail for us to reproduce and fix the issue
  • Allow reasonable time for remediation before any disclosure

Report vulnerabilities to security@juicefactory.ai. We acknowledge receipt within 24 hours and aim to provide an initial assessment within 72 hours.

Verify our claims yourself

Sign up, review the DPA, inspect the sub-processor list, and test the zero-retention API. Starter credit includes up to 100 standard requests.