TRUST CENTER

Trust starts with verifiable status

We separate implemented controls, deployment-specific behavior, plans, and claims that are not yet verified.

PUBLIC REGISTER

Current control status

Status applies only to the stated scope. Missing evidence is not replaced by a marketing promise.

ControlStatusScopeEvidence / notes
Public-site TLSImplementedyasnora.ruHTTPS and redirect behavior are checked during production deployment.Verified: 2026-08-22
Encryption at restDeployment-dependentDefined by the selected deploymentNot claimed universally without evidence for the specific infrastructure.Owner: security@yasnora.ai
Role-based accessNot verifiedApplication and enterprise deploymentsCurrent implementation evidence is not yet connected to the public site.Owner: security@yasnora.ai
Workspace isolationDeployment-dependentApplication; deployment-dependentServer-side tenant and workspace scope is covered by automated tests; independent production testing is pending.Owner: security@yasnora.ai
Action auditNot verifiedPlan- and deployment-dependentNot presented as available until confirmed by the application registry.Owner: security@yasnora.ai
BackupsDeployment-dependentSpecific production deploymentRecovery parameters and targets are defined per deployment or contract.Owner: security@yasnora.ai
Data location and residencyNot verifiedLocal / Hybrid / permitted external modesUniversal Russian residency is not claimed: stores, logs, backups, providers, and the active deployment policy require evidence.Owner: privacy@yasnora.ai
External AI routingDeployment-dependentOnly under permitted configurationTests prevent prohibited external fallback; the active production policy is not verified.Owner: privacy@yasnora.ai
Retention and deletionNot verifiedDepends on data type and deploymentThe retention matrix and deletion chain remain under review.Owner: privacy@yasnora.ai
SSO / SCIMPlannedEnterprise deploymentsNot represented as an implemented capability.Owner: support@yasnora.ai
Server-side routing policyDeployment-dependentYasnora Auto and AI gatewayCode applies policy, residency, and capability before economics; production activation is not verified.Owner: security@yasnora.ai
Routing telemetry minimizationDeployment-dependentRouting decisions and outcomesThe artifact records technical metadata without prompt text; the full logging audit is pending.Owner: security@yasnora.ai