yebo®
Security architecture

Security architecture overview

How identity, encryption, isolation, and oversight work end-to-end across Yebo OS — with a mapping to the frameworks enterprise reviewers expect.

01

Principles

Security is built into every layer, not bolted on. Every model runs least-privilege, every tenant is isolated, and every decision is logged immutably. Governance is enforced at runtime, not just documented.

02

Identity & access

  • Identity and access management with role-based scoping
  • Least-privilege data access granted per model and per integration
  • Human oversight checkpoints on sensitive or high-risk decisions
03

Data protection

  • Encryption at rest and in transit
  • Data isolation by tenant
  • Encrypted connectors and credential vaulting
  • Immutable audit logging with a standing, queryable trail
04

Model security

  • Model sandboxing with scoped data access
  • Explainability requirements on model output
  • Human-in-the-loop routing for flagged decisions
05

Control alignment

Yebo OS controls are designed to align with the frameworks enterprise reviewers use. This is an alignment statement to speed your assessment — not a certification claim. Formal SOC 2 / ISO 27001 audits are not yet held.

ControlSOC 2 (Trust Services)ISO 27001 (Annex A)
Identity & access managementCC6.1 – CC6.3A.5 / A.8
Encryption at rest & in transitCC6.7A.8.24
Immutable audit loggingCC7.2 – CC7.3A.8.15
Data isolation by tenantCC6.1A.8.22
Human oversight checkpointsCC1.3 / CC2.1A.5.4
Change managementCC8.1A.8.32

Mapping is indicative alignment, provided to accelerate a reviewer's assessment. It does not assert an audited certification.

06

Roadmap

A path to post-quantum cryptography before it becomes mandatory, and formal certification once the audit process completes. This page is updated when that status changes.

Full version

This is the public overview. Talk to us for the full security pack under NDA: penetration-test summary, completed SIG / CAIQ questionnaire, sub-processor list, incident-response runbook, and the DPA.

TALK TO US ↗
NEXT STEP

See where your own systems stand before you see Yebo in action