90 Days Gen AI Risk Trial -Start Now
Book a demo
Marketing·Pro $59/mo/seat (annual); Business custom; 7-day trial·jasper.ai

Jasper

Jasper is an enterprise AI marketing platform with brand voices, marketing agents, a no-code app builder, and governance controls used by marketing teams to produce on-brand content at scale.

Risk Score
Medium
4/10

Independent assessment across data handling, compliance, security and transparency.

Overview

Jasper (jasper.ai) is a marketing-focused AI platform offering the Canvas authoring surface, marketing agents, brand voices, knowledge assets, and audience profiles. The Business tier adds a no-code AI App Builder, Jasper Grid for workflows, API access, and enterprise governance. Jasper markets itself as SOC 2, GDPR, PCI, DPA, and CCPA compliant, with SSO, audit logs, and granular permissions for IT. Key enterprise controls: Jasper states that company data and outputs are never used to train third-party LLMs, and SOC 2 reports are available via security.jasper.ai. HIPAA is not claimed. Risk is moderate: marketing content often references confidential product roadmaps, pricing, and campaign data, and prompts route through third-party foundation models. Best used with brand-voice guardrails, SSO, and clear policy on confidential input.

Risk factors

3
  • Cloud-based service with potential third-party data sharing
  • User-generated content may be used for model training
  • Requires user data for content generation features

Recommendations

7
  • Require Business plan for any org-wide deployment to enable SSO, audit logs, and governance
  • Block use for PHI and other regulated data categories Jasper does not cover
  • Enforce a policy against pasting unreleased product or financial data into prompts
  • Request SOC 2 report via security.jasper.ai before procurement
  • Use brand voices and knowledge assets to reduce ad-hoc prompt leakage
  • Legal review of generated copy for claims, disclosures, and trademark compliance
  • Integrate via SSO/SCIM and disable personal-email signups on corporate domains

Data handling

Storage
Customer content and brand assets stored on Jasper-managed cloud infrastructure; prompts processed through third-party foundation LLMs under contractual controls.
Retention
Retained only as long as necessary for service purposes or legal obligations; policy does not publish specific retention timeframes.
Training on inputs
Company data and outputs are never used to train third-party LLMs per Jasper enterprise documentation.