Every action has a right, a reason, and a trace.
Yayaw starts from one simple rule: nobody, human or assistant, acts without a right you granted, and nothing happens without leaving a trace.
Six protections, all in the code.
Sign-in
Passwordless sign-in with passkeys or a magic link, two-factor authentication, several sessions under your control, and bot protection on the forms.
Rights
Groups, roles, and policies. Every access is decided on the server, and every refusal is explained and recorded.
Assistants
One permission per action, a written reason for every change, a dry run before applying, a check that nothing moved in the meantime, and access you can revoke.
Payments
Cards never go through Yayaw: they stay with our payment provider. Each payment notification is handled once, and checkout checks rights and two-factor again on the server.
Files & data
Files are uploaded through signed, short-lived links. Draft previews are signed, invitation tokens are stored hashed, and the data API is rate limited.
Secrets & releases
Secrets live outside the database. Before each release, dependencies are audited for known vulnerabilities, admin access is audited, and more than 2,000 tests run.
Clear about who does what.
What Yayaw takes care of
No access without a granted right, checked on the server
Every change made by an assistant carries a written reason
A dated log of who did what
Your customers' cards never reach Yayaw
Hosting and updates
What stays in your hands
Protecting your devices and your access
Approving what goes live
Deciding who gets which rights
The terms of the assistant provider you choose
Your own privacy obligations toward your customers
Hard questions. Straight answers.
Do you hold a certification such as SOC 2 or ISO 27001?
No. Yayaw is made by an independent publisher and holds no certification. This page only describes mechanisms that really exist in the product, and we answer audit questions at [email protected].
Where is my data hosted?
At Yayaw. The country and the host are stated on this page before the paid plans open.
Can an assistant break everything?
It works on drafts, tests a change before applying it, and cannot overwrite what someone changed in the meantime. Pages and data tables keep their history, so you go back.
How do I cut off an assistant?
You revoke its access and it loses its hand at once. It never had more rights than the account that connected it.
What about passwords?
Yayaw favors sign-in without a password, by passkey or magic link, and adds two-factor authentication. Invitation tokens are stored hashed, never in clear.
I found a vulnerability. What now?
Write to [email protected] with what you found and how to reproduce it.