Loading
Every jam stays inside your estate. The AI Jammer runs on FocusJam's own GPUs. Media is encrypted end-to-end. Nothing — not a single transcript word, not a frame of video — leaves your boundary to a third-party AI service.
Most conferencing AI phones home to OpenAI, Google, or another cloud vendor every time someone speaks. FocusJam does not. All speech-to-text, intelligence, and voice synthesis runs on FocusJam-operated GPUs — $0 AI or media data leaves your estate to any third party.
AES-GCM-256 insertable streams encrypt every jam end-to-end by default. The SFU media server routes packets it cannot decrypt. The AI Jammer is a trusted in-room key-holder — it hears what participants hear, inside the encrypted session, not outside it.
Granular controls over who enters, how they're verified, and what permissions they carry — from signed invite tokens to real-time lobby decisions.
HMAC-signed tokens are single-use or multi-use, and can be bound to a specific email address. A leaked link is useless once redeemed or expired.
Anyone who isn't on the OIDC allow-list lands in the lobby. The host admits or denies — no one enters the jam unannounced.
Lock a room mid-jam to prevent new entrants. Optionally require a PIN — stored as a SHA-256 hash, raw value never persisted anywhere.
Named invitees authenticate via OIDC and carry verified identity. Guest participants enter under a scoped, time-limited credential that cannot escalate privileges.
Participant tokens carry only what they need — no room admin, create, list, or record grants by default. Capabilities are additive, never inherited.
Hosts see the full room roster and lobby queue. Guests see only what the host chooses to surface. The AI Jammer's presence is always disclosed to all participants.
Privacy controls are slash commands away. When you pause or go off the record, that speech never touches the AI pipeline, transcript, notes, or any artifact — it is discarded at the source.
/pause — suspends AI capture; speech discarded before transcription/offrecord — marks segment off the record; not transcribed, not storedFocusJam is built on hardened, auditable, GitOps-driven infrastructure — every layer chosen for security and sovereignty.
All admin and agent planes run over a zero-trust private overlay network. No public exposure for internal services — every connection is mutually authenticated and encrypted in transit.
All runtime secrets are sourced from Azure Key Vault via ExternalSecret + SOPS (AGE). No credentials are committed to source control — ever.
Public-facing endpoints sit behind Cloudflare for DDoS mitigation and optional Turnstile bot challenge. The real-time media path bypasses Cloudflare to protect latency.
Every infrastructure change flows through Git and ArgoCD — no manual kubectl, no configuration drift. Talos Linux provides an immutable, minimal attack surface for the control plane.
Enterprise customers can run the full FocusJam stack on their own hardware or private cloud. Your data never leaves infrastructure you own and operate.
Container images are built with BuildKit, scanned for CVEs before deployment, and signed. SBOMs are generated per release so you can audit every dependency in your estate.
FocusJam uses Keycloak (FocusPass) as its OIDC identity provider. Enterprise customers can federate their own IdP — Active Directory, Okta, Google Workspace — in minutes. Authentication is handled before a participant ever enters a jam.
We collect only what is necessary for the session. No advertising profiles, no behavioral analytics, no cross-session tracking.
Your meeting data belongs to you. It runs on infrastructure you choose, under jurisdiction you control. Enterprise customers can self-host everything.
Every component — token, service account, API key — carries only the minimum grants it needs. Elevation is explicit, auditable, and time-bounded.
The AI Jammer always announces its presence. All capture controls and their effects are documented and predictable. No hidden recording or processing.
FocusJam is architected to GDPR data-minimisation and data-sovereignty principles. SOC 2, GDPR, and HIPAA formal audit programmes are on our roadmap — these are posture commitments, not current certifications.
Enterprise customers get a fully self-hosted FocusJam deployment — your data, your hardware, your jurisdiction. Talk to us about requirements, security review, and custom SLAs.