Security practices
Controls implemented in the product today.
OAuth tokens and provider API keys are sealed with AES-256-GCM using a fresh 96-bit nonce per secret.
All client and sub-processor traffic is served over TLS.
Sessions, files, memories, and the credit ledger are scoped to the authenticated owner on every read and write.
Agent code runs inside per-session isolated containers, not on shared application hosts.
How we handle your data
Your prompts, files, and generated content are never used to train Yani's models or shared with model providers for training.
You can export a copy of your data or request deletion at any time from Settings → Data controls. Request account deletion; we action verified requests within 30 days.
Sub-processors
Third parties that process data on our behalf. This list reflects the providers configured on this deployment.
Primary datastore (accounts, sessions, billing ledger).
Ephemeral cache, rate limits, and real-time streams.
Compliance roadmap
On our roadmap — not yet certified. We will only claim a certification once it is independently audited.
Independent audit not yet completed.
Certification not yet held.
Report a security issue
Found a vulnerability? We want to hear from you.
[email protected]