Executive Summary
AI-generated analysis for Jasper
Jasper (jasper.ai) is an AI-powered content creation platform assessed at Risk Tier 3 (Moderate Risk), reflecting a vendor with meaningful positive security signals alongside notable transparency gaps that warrant attention before onboarding at a medium data access level. On the positive side, Jasper demonstrates several encouraging characteristics:
Key Findings
- Domain infrastructure is healthy, with valid DNS, properly configured email records, and all three recommended security headers (HSTS, CSP, X-Frame-Options) present.
- The domain carries a clean threat intelligence reputation with no listings on SURBL, Spamhaus DBL, or Malware detection service, and no active malware URLs detected.
- TLS is configured using TLSv1.3 with AES-256-GCM — a strong, modern cipher suite with no weak protocols detected.
- Jasper claims SOC 2 compliance via a dedicated trust portal (security.jasper.ai) powered by Drata, which is a positive signal of a structured compliance program, pending independent confirmation.
- No sanctions matches, FDIC enforcement actions, or SEC enforcement filings were found — all expected and appropriate for a SaaS vendor of this type.
- Infrastructure is confirmed to be served through Cloudflare, a reputable CDN, and no known CVEs were identified on exposed infrastructure. Several gaps reduce confidence and elevate the risk tier. The most significant concern for an AI-native vendor is the absence of a publicly accessible AI data usage policy — no training commitment, retention terms, or third-party model provider disclosures were discoverable through automated scanning. This is a material gap for any buyer sharing content or proprietary data with an AI platform. Additionally, Jasper does not publish a subprocessor list, limiting supply chain visibility. The HTTP security scanner returned a poor HTTP security grade (D-, 25/100) on the marketing site, and 13 open ports were detected — above the typical SaaS baseline. The TLS certificate expires in 52 days, warranting confirmation of renewal. A historical media article referencing an entity named "Jasper" in connection with unauthorized government network access was identified but assessed as referencing a different, unrelated entity after relevance filtering. Overall, Jasper presents a moderate risk profile consistent with a growing AI SaaS vendor that has invested in core security infrastructure but has not yet achieved the compliance transparency maturity expected for medium data access engagements. A conditional approval path is available, contingent on resolving the AI data policy and subprocessor disclosure gaps.
Independence Statement
All evidence in this report was independently sourced from external data repositories, public registries, and open-source intelligence tools without vendor participation or notification.