How JSON Holdings LLC (d/b/a IsotopeReady) protects your nuclear compliance data in IsotopeReady.
Last updated: March 24, 2026
IsotopeReady handles sensitive nuclear supply chain data — bid values, compliance certifications, HALEU traceability records, and ITAR-adjacent documentation. We treat security not as a checkbox but as a core operational requirement. This document describes the technical and organizational controls we maintain to protect your data.
For security vulnerability reports, contact [email protected]. We commit to acknowledging reports within 48 hours and resolving critical vulnerabilities within 7 days.
IsotopeReady maintains comprehensive audit logs to satisfy NQA-1, 10 CFR 50 Appendix B, and ITAR recordkeeping requirements. Every audit log entry is immutable — no application user or administrator can modify or delete audit records.
Auditor role users have read-only access to all audit logs within their tenant, facilitating external compliance audits without requiring ShopAdmin privileges.
IsotopeReady processes compliance documents through an OCR pipeline (Tesseract). Security controls for this pipeline:
We conduct annual third-party penetration tests of the IsotopeReady platform. Findings are remediated according to severity: Critical within 24 hours, High within 7 days, Medium within 30 days. Test reports are available to Premium tier customers under NDA upon request.
We welcome responsible disclosure of security vulnerabilities. To report a vulnerability:
IsotopeReady operates under or works toward the following security standards:
For security inquiries, vulnerability reports, or to request our security documentation:
Email: [email protected]
JSON Holdings LLC (d/b/a IsotopeReady)
United States