What is Juno's certification and compliance status?
- Juno is ISO/IEC 27001 certified; our Trust Center also lists GDPR and CCPA under compliance. The ISO/IEC 27001 certificate is available on request through the same page. A penetration test report and a network diagram are available on request as well. SecurityScorecard grades Juno A. The page carries the date it was last reviewed.
Which model provider processes our data, and what does the assistant see?
- OpenAI is named as a sub-processor on our Trust Center, alongside Datadog, SendGrid, Google Cloud and MongoDB. An assistant connected over MCP reaches only the data the person's Juno role already permits. Connecting does not open new categories of data, and tools that person cannot use do not appear.
Which identity providers do you support, and how is provisioning handled?
- Juno supports SAML 2.0 single sign-on with Okta, Microsoft Entra, Google and any SAML 2.0 compliant provider. Your HRIS or HCM syncs over SCIM on a schedule, with sync logs. Auto-provisioning is gated on the email domains you allow, and Juno never stores your users' passwords for integrated services.
Can we limit an administrator to one area?
- Yes. Roles scope by domain, so an administrator can hold People and nothing else. The domains are People, Content, Budget, Development, Engagement, Events, Channels, Company Automations and Platform. Effective access in an area is the higher of the base role and the domain role. A blocked user authenticates and sees no content.
What does each connector access, and who approves it?
- Each integration is published with what it does, who consents and the auth model, and the consenting party is named exactly: a Google Workspace admin, a Slack workspace admin, or the meeting organizer for calendars. Juno requests only the scopes a feature needs, and each documentation page lists the exact permission strings.
What can the AI do without a human?
- It can read within the permissions of the person who connected it, and it can prepare work. Finishing the work is a separate step that belongs to a person. Every write action stops at an approval card that resolves the audience and can be edited, and nothing runs until a person confirms. Automations are created paused.
How do we revoke access?
- Every integration can be disconnected from Juno or revoked from the provider's own admin console, and each documentation page carries the revocation steps. An MCP connection is revocable from the client that holds it. Removing someone in your directory removes their access, because provisioning follows the directory.
Where are the documents, and who can we talk to?
- The penetration test report, the network diagram and the ISO/IEC 27001 certificate sit behind a request on our Trust Center, which is also where the sub-processor list and the control families are published. If a questionnaire row is not answered there, request the document on the Trust Center or book a demo.
How is Juno priced?
- Pricing is published on the pricing page.