Skip to main content

Security

Security at Yori

Last updated: May 9, 2026

Draft notice: This is a draft policy. Please have it reviewed by qualified counsel before relying on it commercially.

Security and the trust of our customers' businesses is foundational to Yori. This page describes the technical and organisational measures we use to protect your data.

1. Architecture

Yori is a cloud-hosted SaaS application. Application servers, database, and background workers run in isolated environments with least-privilege access policies. We separate production from non-production environments and never use real customer data in development.

2. Encryption in transit and at rest

All traffic between your browser and Yori is encrypted with TLS 1.2 or higher. Data at rest in our managed database and object storage is encrypted using AES-256.

3. OAuth & Google API scopes

We connect to your Google Business Profile via OAuth 2.0. We request only the scopes required to read your reviews and post replies (primarily business.manage). We never request scopes beyond what is necessary, and you can revoke our access at any time from your Google account settings.

4. Authentication

Customer authentication is handled through a managed identity provider that supports email/password and social sign-in with industry-standard password hashing and account-recovery flows. We strongly recommend enabling multi-factor authentication.

5. Access controls

Access to production systems is restricted to a small number of engineers, requires multi-factor authentication, and is logged. Engineers access customer data only when necessary to support, debug, or operate the service, and only with appropriate authorisation.

6. Hosting & subprocessors

Production infrastructure runs on tier-1 cloud providers in regions chosen for availability and data-protection compliance. We maintain a list of subprocessors (hosting, database, AI model providers, payment processing, error monitoring) and update it as it changes; an up-to-date list is available on request.

7. Vulnerability reporting

If you believe you have found a security issue in Yori, email security@yori.app with reproduction steps. We commit to acknowledging reports within two business days and to working with researchers in good faith. Please do not publicly disclose issues before we've had a reasonable chance to remediate.

8. Incident response

We maintain an incident-response plan covering detection, containment, eradication, recovery, and customer notification. In the event of a confirmed breach affecting your data, we will notify affected customers without undue delay in accordance with applicable law.

9. Compliance roadmap

Yori is on a path toward SOC 2 Type II readiness. We already follow many of the underlying controls and intend to formalise our attestation as the company scales. Customers with specific compliance requirements are welcome to email us to discuss.

10. Contact

Security questions or concerns? Email security@yori.app.