Protection
Security
How the platform is protected today, and the enterprise security roadmap.
Effective / reviewed: Reviewed 2026 — draft pending legal counsel sign-off
Note on claims
This page describes the security posture Yangu Systems is building toward. Items marked (planned) are not yet available. No certification, audit outcome or compliance status is claimed unless it is explicitly published with evidence.
Encryption
- Traffic is served over HTTPS/TLS.
- Stored data is encrypted at rest by the hosting platform.
- PLACEHOLDER — key management and customer-managed key options.
Authentication
- Managed authentication with secure session handling.
- Password policies and email verification.
- SSO / SAML for enterprise plans (planned).
Access control
- Server-side authorisation on every privileged operation.
- Row-level data isolation between organisations.
- Least-privilege service credentials.
Secure hosting
- Managed cloud infrastructure with isolated environments.
- Automated patching of platform dependencies.
- PLACEHOLDER — hosting regions and data residency options.
Backups
- Automated database backups on a rolling schedule.
- Restore procedures tested periodically.
- PLACEHOLDER — RPO/RTO targets.
Audit logging (planned)
Tamper-evident logs of administrative and AI-initiated actions, exportable for enterprise review.
Role-based permissions
Roles are stored separately from user profiles and evaluated server-side, so permissions cannot be escalated from the browser.
Multi-factor authentication (planned)
TOTP and passkey support, with the option to enforce MFA organisation-wide.
Enterprise security roadmap
- Data Processing Agreement (DPA)
- Published subprocessor list
- SOC 2 readiness programme
- ISO 27001 readiness programme
- Enterprise SLA
- Security whitepaper
- Incident response commitments and notification timelines
- Customer-visible audit logs
- Third-party penetration testing summaries
Roadmap items are intentions, not current certifications.
Reporting a vulnerability
Report suspected vulnerabilities to PLACEHOLDER — security@. Please include reproduction steps and allow reasonable time to remediate before public disclosure. We do not pursue good-faith researchers who follow this process.