Security

Every action has a right, a reason, and a trace.

Yayaw starts from one simple rule: nobody, human or assistant, acts without a right you granted, and nothing happens without leaving a trace.

Six protections, all in the code.

Sign-in

Passwordless sign-in with passkeys or a magic link, two-factor authentication, several sessions under your control, and bot protection on the forms.

Rights

Groups, roles, and policies. Every access is decided on the server, and every refusal is explained and recorded.

Assistants

One permission per action, a written reason for every change, a dry run before applying, a check that nothing moved in the meantime, and access you can revoke.

Payments

Cards never go through Yayaw: they stay with our payment provider. Each payment notification is handled once, and checkout checks rights and two-factor again on the server.

Files & data

Files are uploaded through signed, short-lived links. Draft previews are signed, invitation tokens are stored hashed, and the data API is rate limited.

Secrets & releases

Secrets live outside the database. Before each release, dependencies are audited for known vulnerabilities, admin access is audited, and more than 2,000 tests run.

Clear about who does what.

What Yayaw takes care of

No access without a granted right, checked on the server

Every change made by an assistant carries a written reason

A dated log of who did what

Your customers' cards never reach Yayaw

Hosting and updates

What stays in your hands

Protecting your devices and your access

Approving what goes live

Deciding who gets which rights

The terms of the assistant provider you choose

Your own privacy obligations toward your customers

Hard questions. Straight answers.

Do you hold a certification such as SOC 2 or ISO 27001?

No. Yayaw is made by an independent publisher and holds no certification. This page only describes mechanisms that really exist in the product, and we answer audit questions at [email protected].

Where is my data hosted?

At Yayaw. The country and the host are stated on this page before the paid plans open.

Can an assistant break everything?

It works on drafts, tests a change before applying it, and cannot overwrite what someone changed in the meantime. Pages and data tables keep their history, so you go back.

How do I cut off an assistant?

You revoke its access and it loses its hand at once. It never had more rights than the account that connected it.

What about passwords?

Yayaw favors sign-in without a password, by passkey or magic link, and adds two-factor authentication. Invitation tokens are stored hashed, never in clear.

I found a vulnerability. What now?

Write to [email protected] with what you found and how to reproduce it.

A security question? Ask us.

Yayaw