1. Scope and contractual commitments
PCGROUP, LLC / JBComm provides AIMarket / OmniReach under the Agreement. This overview identifies safeguard categories; it does not represent that each control is implemented or verified for every Service. Binding commitments require evidence, signed terms, and completed DPA Annex E.
No certification, independent audit status, penetration-testing certification, comprehensive regulatory compliance, uptime SLA, or recovery-time guarantee is asserted.
2. Identity, access, and tenant separation
- Authentication appropriate to enabled service access.
- Authorization/least privilege aligned with permitted purposes and assigned responsibilities.
- Tenant separation protecting against unauthorized cross-customer access, including permission-aware tenant AI.
- Appropriate access review/removal when duties or Customer authority change.
These are protective outcomes; applicable measures and scope follow the Agreement and completed DPA Annex E. Customers remain responsible for their permissions and credentials.
3. Data minimization and handling
- Minimize processing to necessary authorized information.
- Protect supported transmission channels, including encryption in transit where supported and verified; no universal or end-to-end claim.
- Appropriate activity/audit records for permitted administration and investigation, with role/purpose-based retention.
- Return, deletion, and lawful minimal suppression under the DPA; identifiable suppression remains restricted Personal Data.
Ownership and AI-use limits continue; this overview authorizes no identifiable-data shared-model training.
4. Development and vendor risk
Safeguard categories include appropriate secure-development review, evaluation of changes affecting data handling, personnel confidentiality, and relevant vendor-risk assessment. Suppliers need appropriate processing contracts/authorization. Specific measures and supporting information follow applicable signed commitments.
No test cadence, supplier stack, certification, or specific method is promised.
5. Backups and incidents
Backup/recovery and incident categories must match actual contracted responsibilities. You are responsible for backups of Customer Data unless a paid backup/add-on explicitly states otherwise in writing. This customer duty does not replace our applicable processing obligations.
The DPA governs applicable law-based incident notice and cooperation. Actual backup scope, expiry/deletion, and restoration responsibilities follow the applicable agreement and completed DPA annexes. No fixed recovery objective or retention period is stated.
6. Evidence and questions
Request relevant contractual security information at sales@jbcomm.net. Protect other customers, confidential information, and service security while honoring applicable audit duties. No independent report is represented as available.
Agreed controls, service scope, responsibilities, and DPA measures govern the applicable Services. Existing liability cap, indemnity, and Arizona law are not changed.