TRUST CENTER
Trust starts with verifiable status
We separate implemented controls, deployment-specific behavior, plans, and claims that are not yet verified.
PUBLIC REGISTER
Current control status
Status applies only to the stated scope. Missing evidence is not replaced by a marketing promise.
| Control | Status | Scope | Evidence / notes |
|---|---|---|---|
| Public-site TLS | Implemented | yasnora.ru | HTTPS and redirect behavior are checked during production deployment.Verified: 2026-08-22 |
| Encryption at rest | Deployment-dependent | Defined by the selected deployment | Not claimed universally without evidence for the specific infrastructure.Owner: security@yasnora.ai |
| Role-based access | Not verified | Application and enterprise deployments | Current implementation evidence is not yet connected to the public site.Owner: security@yasnora.ai |
| Workspace isolation | Deployment-dependent | Application; deployment-dependent | Server-side tenant and workspace scope is covered by automated tests; independent production testing is pending.Owner: security@yasnora.ai |
| Action audit | Not verified | Plan- and deployment-dependent | Not presented as available until confirmed by the application registry.Owner: security@yasnora.ai |
| Backups | Deployment-dependent | Specific production deployment | Recovery parameters and targets are defined per deployment or contract.Owner: security@yasnora.ai |
| Data location and residency | Not verified | Local / Hybrid / permitted external modes | Universal Russian residency is not claimed: stores, logs, backups, providers, and the active deployment policy require evidence.Owner: privacy@yasnora.ai |
| External AI routing | Deployment-dependent | Only under permitted configuration | Tests prevent prohibited external fallback; the active production policy is not verified.Owner: privacy@yasnora.ai |
| Retention and deletion | Not verified | Depends on data type and deployment | The retention matrix and deletion chain remain under review.Owner: privacy@yasnora.ai |
| SSO / SCIM | Planned | Enterprise deployments | Not represented as an implemented capability.Owner: support@yasnora.ai |
| Server-side routing policy | Deployment-dependent | Yasnora Auto and AI gateway | Code applies policy, residency, and capability before economics; production activation is not verified.Owner: security@yasnora.ai |
| Routing telemetry minimization | Deployment-dependent | Routing decisions and outcomes | The artifact records technical metadata without prompt text; the full logging audit is pending.Owner: security@yasnora.ai |