Security & Trust

Built for the regulated reality you actually live in.

Encryption at rest and in transit. Per-workspace data isolation enforced at the database layer. Unified suppression across channels.

Encryption and isolation

TLS encryption in transit on every connection. Per-workspace data isolation enforced at the database layer, not just the app layer.

Least-privilege access

Only you and your teammates. Production access is restricted and every action against production data is audit logged.

Compliance posture

CCPA / GDPR ready. DPA available on request. TCPA enforcement built into the send layer: prior express written consent before any call or text, quiet hours applied in the recipient's local time zone, and per-channel opt-out honored on the spot.

Your data, your control

Access, export, correct, delete, restrict, object - submit requests in-app or email privacy@yapii.com. We respond within 30 days.

Operational practices

What we do, every day.

  • Mandatory 2FA on every account with production access.
  • Full audit trail per contact: who imported, who edited, who sent.
  • We notify affected customers within 24 hours of any incident involving their data.
  • Vendor due-diligence on every subprocessor before signing.

Subprocessors

Named subprocessors, regions, data scope, and DPA status are provided on request. Email privacy@yapii.com and we will send the full list with our DPA.

  • Cloud infrastructure and object storage
  • Payment processing (when pricing launches)
  • Text message and voice delivery
  • Email delivery
  • Public-records data enrichment
  • AI model hosting (with local fallback)

Compliance

Where we are, what's coming.

Live

CCPA / GDPR ready

Customer-facing privacy controls and DSR workflow live today.

Planned

Independent security audit

Formal third-party certification is on the roadmap. We will publish the scope and timeline once an audit is scheduled.

Live

TCPA enforcement

Consent required before any call or text, quiet hours in the recipient's local time zone, per-channel opt-out. Audit trail per contact.

Want the full security packet?

We send our DPA and the named subprocessor list on request.