Security

How we handle your files and scripts, what is protected, and what is not.

Render isolation

Every .blend or script runs only inside a container created for that job and destroyed afterwards. The container has no network access, runs as an unprivileged user (not root) with all Linux capabilities dropped and privilege escalation disabled, is limited in CPU, memory, process count and wall-clock time, and sees exactly one GPU. It cannot reach host files, the Docker daemon or other users' data.

The API

The API is not exposed to the internet directly; it is reachable only through a Cloudflare tunnel (TLS). API keys are stored as hashes. Key issuance, uploads and job submission are rate-limited; the free tier has a daily GPU-time quota per key and per network. Responses carry protective headers and keys are never accepted in query strings.

Data

Inputs, intermediate data and results are deleted 24 hours after last use. Logs keep only sizes, timings and failure reasons, never contents. Nothing is used for training.

What is not covered

Container isolation relies on the Linux kernel; we do not run an additional sandbox such as gVisor. For confidential production work, contact us before uploading. The service is a free beta without an availability guarantee.

Reporting

Found a vulnerability? Tell us at contact@jasmylab.com. We appreciate testing that does not touch other users' data.

JANCTION Render v0.1.0 · JasmyLab Inc.