Encryption in transit
ToolJet uses TLS to encrypt data transmitted between users and its servers, protecting information as it moves.
ToolJet Security
Protect your data with encryption, access controls, and security practices across the application lifecycle. Choose where your apps and AI run, with deployment options that fit your requirements.
Visit the ToolJet Trust CenterBuilt for your security review
Review SOC 2 audit information, ISO 27001, and GDPR compliance resources in our Trust Center.
Explore our controls and policiesSecurity across your application lifecycle
ToolJet combines encryption, role-based permissions and auditability for internal apps built visually, with AI or through coding agents. Match the controls to your plan, review generated queries and test access before releasing an app.
ToolJet uses TLS to encrypt data transmitted between users and its servers, protecting information as it moves.
Sensitive data stored on ToolJet's servers is encrypted at rest. For Self-hosted deployments, configure storage and infrastructure protections for your environment.
Control access to apps and resources with role-based permissions. Give users and connected accounts only the access they need.
Authentication and access controlsData source credentials are encrypted using AES-256-GCM and are not shared with AI servers or model providers. On Self-hosted deployments, they remain inside your deployment.
Credential security detailsUse the audit logging and observability controls available for your plan to review activity and support security monitoring. Set appropriate access and retention for logs.
Our privacy policy explains data collection, use, retention, and deletion requests, including applicable legal retention requirements. Contact us to request deletion of your account or personal information.
Read the privacy policySecurity is an ongoing practice
Review our security controlsWe monitor our systems for suspicious activity and security incidents. Our response plan covers containment, communication with affected parties, and remediation to help prevent recurrence.
Our Trust Center documents change-management and application security controls. For your own apps, review changes before release, separate development from production, and keep deployment dependencies up to date.
Review the app release lifecycleShared responsibility
Protect your accounts and maintain the infrastructure you operate.
AI on your terms
Control the deployment, the gateway, and the model endpoint to meet your data requirements.
Builder BYOK is available on Enterprise plans for both Cloud and Self-hosted. Requests use ToolJet's managed AI server with your provider keys and do not consume ToolJet AI credits; provider usage is billed separately. On-premises gateway hosting is a separate Self-hosted Enterprise add-on. Fully internal inference also requires a supported local model endpoint.
Connection direction
The gateway cannot initiate a connection into your deployment. Replies return over the connection your deployment opens.
Outbound-only connectivity controls network access, not request contents. AI requests can include context from the data sources you make available. Review AI data usage.
ToolJet does not use customer data to train or improve AI models, and does not permit its third-party LLM providers to do so.
AI data usage policyRequests can include prompts, app context, schemas, and data read through connected credentials. Restrict data-source permissions; discovery is not limited to schemas. Treat logs containing prompts or responses as sensitive.
Example deployment isolation
Deployment guideEnterprise plans include multiple deployments. Run development, staging, and production as separate ToolJet instances, with AI enabled or disabled for each deployment.
Build with AI using test or sanitized data and limited data-source permissions.
Pull app definitions with GitSync. Configure staging credentials and test before release.
Promote reviewed apps with production-only credentials and controlled access.
Promote apps with GitSync. Configure secrets separately in each deployment.
Self-hosted Enterprise add-on
Plan an air-gapped deploymentWith the air-gapped deployment add-on, ToolJet runs without internet access—including its licensing system.
Keep required data sources, identity services, and Git repositories within your isolated network.
For ToolJet-managed AI, allow outbound HTTPS to api-gateway.tooljet.ai and python-server.tooljet.ai, as listed in the AI setup guide. Your selected data sources, model endpoints, Git hosts, email services, and identity providers may require additional access.
Environment variables let you disable telemetry, update checks, and other optional outbound features. Review the configuration reference for your release.
ToolJet AI and coding agents connected through ToolJet MCP create native app configurations that remain editable in the visual builder. Review generated queries and permissions, restrict connected credentials, and test releases before production. Team includes SSO, audit logs and GitSync; Enterprise adds SCIM and multiple deployments. Your team remains responsible for reviewing each app and configuring the controls available on its plan.
ToolJet uses TLS for data transmitted between users and its servers and encrypts sensitive data stored on its servers at rest. Data source credentials are encrypted using AES-256-GCM. Self-hosted customers configure the network, storage, and access protections for their own infrastructure.
Use role-based permissions to limit access to apps and resources. Audit logging and observability controls available for your plan support security monitoring. Review permissions regularly and configure who can access logs and how long they are retained.
Contact hello@tooljet.com to request deletion of your account or personal information. Our privacy policy explains the request process, retention practices, and applicable legal requirements.
Yes. Self-hosted Enterprise offers an on-premises AI gateway add-on. BYOK is available on Enterprise plans for both Cloud and Self-hosted but does not make inference local. Use the gateway with a supported model endpoint hosted inside your infrastructure to keep AI processing internal. BYOK with an external model provider still sends requests to that provider.
No. Your Self-hosted deployment initiates the outbound connection and authenticates with a key. The hosted gateway cannot initiate an inbound connection to your deployment. Responses return over the deployment-initiated connection; AI requests can still carry the context needed to complete the task.
Yes. Enterprise plans include multiple deployments. Run separate development, staging, and production instances, enable AI only in development, and promote app definitions through GitSync. Configure each instance's data sources and secrets separately. Apps that call external AI services at runtime still need those services, or must have those features removed.
Yes, when your Self-hosted Enterprise plan includes the air-gapped deployment add-on. ToolJet supports offline operation and offline licensing in that configuration. Keep required services inside the isolated network, and use a local gateway and supported local model endpoint if AI is enabled.
Visit the ToolJet Trust Center for compliance information, security controls, AI security posture, and policy resources. Contact our team to review the deployment architecture and Enterprise add-ons required by your organization.
Review your requirements and Enterprise add-ons with our team.