Encryption in transit
ToolJet uses TLS to encrypt data transmitted between users and its servers, protecting information as it moves.
ToolJet Security
Protect your data with encryption, access controls, and security practices across the application lifecycle. Choose where your apps and AI run, with deployment options that fit your requirements.
Visit the ToolJet Trust CenterBuilt for your security review
Review SOC 2 audit information, ISO 27001, and GDPR compliance resources in our Trust Center.
Explore our controls and policiesSecurity across your application lifecycle
Encryption, access controls, and auditability help protect the people, applications, and business data in your workspace.
ToolJet uses TLS to encrypt data transmitted between users and its servers, protecting information as it moves.
Sensitive data stored on ToolJet's servers is encrypted at rest. For Self-hosted deployments, configure storage and infrastructure protections for your environment.
Control access to apps and resources with role-based permissions. Give users and connected accounts only the access they need.
Authentication and access controlsData source credentials are encrypted using AES-256-GCM and are not shared with AI servers or model providers. On Self-hosted deployments, they remain inside your deployment.
Credential security detailsUse the audit logging and observability controls available for your plan to review activity and support security monitoring. Set appropriate access and retention for logs.
Our privacy policy explains data collection, use, retention, and deletion requests, including applicable legal retention requirements. Contact us to request deletion of your account or personal information.
Read the privacy policySecurity is an ongoing practice
Review our security controlsWe monitor our systems for suspicious activity and security incidents. Our response plan covers containment, communication with affected parties, and remediation to help prevent recurrence.
Our Trust Center documents change-management and application security controls. For your own apps, review changes before release, separate development from production, and keep deployment dependencies up to date.
Shared responsibility
Protect your accounts and maintain the infrastructure you operate.
AI on your terms
Control the deployment, the gateway, and the model endpoint to meet your data requirements.
On-premises gateway hosting and BYOK are Self-hosted Enterprise add-ons. BYOK with an external provider still sends requests to that provider; builder BYOK is not available on ToolJet Cloud.
Connection direction
The gateway cannot initiate a connection into your deployment. Replies return over the connection your deployment opens.
Outbound-only connectivity controls network access, not request contents. AI requests can include context from the data sources you make available. Review AI data usage.
ToolJet does not use customer data to train or improve AI models, and does not permit its third-party LLM providers to do so.
AI data usage policyRequests can include prompts, app context, schemas, and data read through connected credentials. Restrict data-source permissions; discovery is not limited to schemas. Treat logs containing prompts or responses as sensitive.
Example deployment isolation
Deployment guideEnterprise plans include multiple deployments. Run development, staging, and production as separate ToolJet instances, with AI enabled or disabled for each deployment.
Build with AI using test or sanitized data and limited data-source permissions.
Pull app definitions with GitSync. Configure staging credentials and test before release.
Promote reviewed apps with production-only credentials and controlled access.
Promote apps with GitSync. Configure secrets separately in each deployment.
Self-hosted Enterprise add-on
Plan an air-gapped deploymentWith the air-gapped deployment add-on, ToolJet runs without internet access—including its licensing system.
Keep required data sources, identity services, and Git repositories within your isolated network.
Without the air-gapped add-on, allowlisting can be limited to ToolJet's AI gateway for ToolJet-hosted services, with optional outbound features disabled. Customer-selected external integrations, model endpoints, Git hosts, or identity providers may need additional access.
Environment variables let you disable telemetry, update checks, and other optional outbound features. Review the configuration reference for your release.
ToolJet uses TLS for data transmitted between users and its servers and encrypts sensitive data stored on its servers at rest. Data source credentials are encrypted using AES-256-GCM. Self-hosted customers configure the network, storage, and access protections for their own infrastructure.
Use role-based permissions to limit access to apps and resources. Audit logging and observability controls available for your plan support security monitoring. Review permissions regularly and configure who can access logs and how long they are retained.
Contact [email protected] to request deletion of your account or personal information. Our privacy policy explains the request process, retention practices, and applicable legal requirements.
Yes. Self-hosted Enterprise offers on-premises AI gateway and BYOK add-ons. Use the gateway with a supported model endpoint hosted inside your infrastructure to keep AI processing internal. BYOK with an external model provider still sends requests to that provider.
No. Your Self-hosted deployment initiates the outbound connection and authenticates with a key. The hosted gateway cannot initiate an inbound connection to your deployment. Responses return over the deployment-initiated connection; AI requests can still carry the context needed to complete the task.
Yes. Enterprise plans include multiple deployments. Run separate development, staging, and production instances, enable AI only in development, and promote app definitions through GitSync. Configure each instance's data sources and secrets separately. Apps that call external AI services at runtime still need those services, or must have those features removed.
Yes, when your Self-hosted Enterprise plan includes the air-gapped deployment add-on. ToolJet supports offline operation and offline licensing in that configuration. Keep required services inside the isolated network, and use a local gateway and supported local model endpoint if AI is enabled.
Visit the ToolJet Trust Center for compliance information, security controls, AI security posture, and policy resources. Contact our team to review the deployment architecture and Enterprise add-ons required by your organization.
Review your requirements and Enterprise add-ons with our team.