All systems operational

Trust center

How Yani protects your data. Everything here reflects what is actually enforced in the product today — no aspirational claims.

Security practices

Controls implemented in the product today.

Encrypted secret vault
Active

OAuth tokens and provider API keys are sealed with AES-256-GCM using a fresh 96-bit nonce per secret.

Encryption in transit
Active

All client and sub-processor traffic is served over TLS.

Per-user data scoping
Active

Sessions, files, memories, and the credit ledger are scoped to the authenticated owner on every read and write.

Isolated execution sandboxes
Active

Agent code runs inside per-session isolated containers, not on shared application hosts.

How we handle your data

We never train on your data

Your prompts, files, and generated content are never used to train Yani's models or shared with model providers for training.

Export & deletion

You can export a copy of your data or request deletion at any time from Settings → Data controls. Request account deletion; we action verified requests within 30 days.

Sub-processors

Third parties that process data on our behalf. This list reflects the providers configured on this deployment.

MongoDBInfrastructure

Primary datastore (accounts, sessions, billing ledger).

RedisInfrastructure

Ephemeral cache, rate limits, and real-time streams.

Compliance roadmap

On our roadmap — not yet certified. We will only claim a certification once it is independently audited.

SOC 2 Type II

Independent audit not yet completed.

Planned
ISO/IEC 27001

Certification not yet held.

Planned

Report a security issue

Found a vulnerability? We want to hear from you.

[email protected]