Security & Trust

Last updated: December 15, 2024

Enterprise-Grade Security

We are committed to protecting your data. Our platform is built with a security-first architecture, ensuring your workflows and intellectual property remain safe at all times.

Security Principles

Visibility

Full transparency into our security posture and data handling practices.

Control

You retain full ownership and control over your workflows and data.

Resilience

Redundant infrastructure designed for high availability and disaster recovery.

1
Data Encryption & Protection

Encryption at Rest

AES-256 encryption for all stored data, including workflows and customer content.

Encryption in Transit

TLS 1.3 for all data transfers between clients and our servers.

Key Management

Strict key rotation policies using industry-standard HSMs.

Isolation

Logical tenant isolation ensures your data is segregated from others.

2
Infrastructure Security

Cloud Hosting

Hosted on secure, SOC 2 compliant cloud infrastructure (AWS/GCP) with global availability zones.

Compliance

Regularly audited for security vulnerabilities. Compliant with GDPR and CCPA data privacy standards.

Network Security

Firewalls, DDoS protection, and strict access control lists (ACLs) protect our perimeter.

Backups & Recovery

Automated daily backups with point-in-time recovery capabilities.

3
Responsible Disclosure

Bug Bounty Program

We value the security community's help in keeping Yapit safe. If you discover a vulnerability, please let us know responsibly.

  • Report via encrypted email to security@yapit.ai
  • Provide sufficient details to reproduce the issue
  • Allow us reasonable time to fix before public disclosure
Safe Harbor

We pledge not to pursue legal action against security researchers who adhere to our disclosure guidelines.

4
Incident Response

Transparency Commitment

In the event of a data breach affecting your information, we will notify you within 72 hours of identification in accordance with GDPR requirements.

Detection

24/7 automated monitoring systems

Analysis

Immediate forensic investigation

Communication

Direct notification to affected users

Security Questions?

Our security team is available to answer any questions regarding our infrastructure and policies.