F O C U S J A M

Loading

Security & Privacy

Sovereign & Private

Your meetings. Your AI.
Your infrastructure.

Every jam stays inside your estate. The AI Jammer runs on FocusJam's own GPUs. Media is encrypted end-to-end. Nothing — not a single transcript word, not a frame of video — leaves your boundary to a third-party AI service.

Zero external AI APIs AES-GCM-256 media encryption Zero-trust networking Self-hostable
$0
AI / media data sent to third parties
3
fully self-hosted AI models
100%
inference on FocusJam estate GPUs
SOVEREIGN AI

The AI Jammer runs on
our hardware. Full stop.

Most conferencing AI phones home to OpenAI, Google, or another cloud vendor every time someone speaks. FocusJam does not. All speech-to-text, intelligence, and voice synthesis runs on FocusJam-operated GPUs — $0 AI or media data leaves your estate to any third party.

  • Whisper runs on-premise for speech recognition
  • Qwen 3.6 27B powers the AI Jammer's intelligence, on your estate
  • Kokoro voice synthesis stays fully in-house
  • Zero API calls to OpenAI, Anthropic, Google, or any external AI service
  • Your conversation content is never used to train external models
END-TO-END ENCRYPTION

The media server
can't read a word.

AES-GCM-256 insertable streams encrypt every jam end-to-end by default. The SFU media server routes packets it cannot decrypt. The AI Jammer is a trusted in-room key-holder — it hears what participants hear, inside the encrypted session, not outside it.

  • Per-room AES-GCM-256 keys, never shared outside the session
  • WebRTC Insertable Streams — encryption before the packet leaves your device
  • SFU media server stays blind to all content
  • AI Jammer participates as a trusted in-room peer, decrypting only what the session permits
ACCESS CONTROL

Every jam is invitation-only by design.

Granular controls over who enters, how they're verified, and what permissions they carry — from signed invite tokens to real-time lobby decisions.

Signed invite tokens

HMAC-signed tokens are single-use or multi-use, and can be bound to a specific email address. A leaked link is useless once redeemed or expired.

Lobby & waiting room

Anyone who isn't on the OIDC allow-list lands in the lobby. The host admits or denies — no one enters the jam unannounced.

Room lock & PIN

Lock a room mid-jam to prevent new entrants. Optionally require a PIN — stored as a SHA-256 hash, raw value never persisted anywhere.

Invitee vs. guest modes

Named invitees authenticate via OIDC and carry verified identity. Guest participants enter under a scoped, time-limited credential that cannot escalate privileges.

Least-privilege tokens

Participant tokens carry only what they need — no room admin, create, list, or record grants by default. Capabilities are additive, never inherited.

Participant visibility controls

Hosts see the full room roster and lobby queue. Guests see only what the host chooses to surface. The AI Jammer's presence is always disclosed to all participants.

CAPTURE CONTROLS

You control what
the Jammer hears.

Privacy controls are slash commands away. When you pause or go off the record, that speech never touches the AI pipeline, transcript, notes, or any artifact — it is discarded at the source.

  • /pause — suspends AI capture; speech discarded before transcription
  • /offrecord — marks segment off the record; not transcribed, not stored
  • 7-day artifact expiry — transcripts and notes auto-expire; delete on demand
  • Download & delete — immediate purge, no shadow copies, no delayed removal
INFRASTRUCTURE

Zero trust, all the way
down the stack.

FocusJam is built on hardened, auditable, GitOps-driven infrastructure — every layer chosen for security and sovereignty.

OpenZiti ZTNA

All admin and agent planes run over a zero-trust private overlay network. No public exposure for internal services — every connection is mutually authenticated and encrypted in transit.

Azure Key Vault secrets

All runtime secrets are sourced from Azure Key Vault via ExternalSecret + SOPS (AGE). No credentials are committed to source control — ever.

Cloudflare edge & Turnstile

Public-facing endpoints sit behind Cloudflare for DDoS mitigation and optional Turnstile bot challenge. The real-time media path bypasses Cloudflare to protect latency.

ArgoCD GitOps on Talos K8s

Every infrastructure change flows through Git and ArgoCD — no manual kubectl, no configuration drift. Talos Linux provides an immutable, minimal attack surface for the control plane.

Self-hostable — Enterprise

Enterprise customers can run the full FocusJam stack on their own hardware or private cloud. Your data never leaves infrastructure you own and operate.

Supply-chain assurance

Container images are built with BuildKit, scanned for CVEs before deployment, and signed. SBOMs are generated per release so you can audit every dependency in your estate.

IDENTITY

Enterprise SSO
from day one.

FocusJam uses Keycloak (FocusPass) as its OIDC identity provider. Enterprise customers can federate their own IdP — Active Directory, Okta, Google Workspace — in minutes. Authentication is handled before a participant ever enters a jam.

  • Keycloak / FocusPass OIDC SSO
  • Federate any SAML 2.0 or OIDC-compliant IdP
  • Per-room OIDC allow-lists for invitee verification
  • Session tokens are short-lived and non-transferable
Azure AD Okta Google Workspace Any OIDC / SAML 2.0 IdP
DESIGN PRINCIPLES

Security is architecture,
not a checkbox.

Data Minimisation

Collect only what you need

We collect only what is necessary for the session. No advertising profiles, no behavioral analytics, no cross-session tracking.

Sovereignty

Your data, your jurisdiction

Your meeting data belongs to you. It runs on infrastructure you choose, under jurisdiction you control. Enterprise customers can self-host everything.

Least Privilege

Minimum grants, always

Every component — token, service account, API key — carries only the minimum grants it needs. Elevation is explicit, auditable, and time-bounded.

Transparency

No hidden recording

The AI Jammer always announces its presence. All capture controls and their effects are documented and predictable. No hidden recording or processing.

FocusJam is architected to GDPR data-minimisation and data-sovereignty principles. SOC 2, GDPR, and HIPAA formal audit programmes are on our roadmap — these are posture commitments, not current certifications.

Enterprise & self-host

Run FocusJam on
your own estate.

Enterprise customers get a fully self-hosted FocusJam deployment — your data, your hardware, your jurisdiction. Talk to us about requirements, security review, and custom SLAs.