Security Policy
Our commitment to maintaining the highest security standards.
At Yozigo, security is at the core of our platform. We are committed to protecting our customers' data and ensuring that our AI visibility tracking services are delivered through a secure and resilient infrastructure. We are SOC 2-aligned.
1. Data protection
We follow industry-standard practices to protect the data we collect. All communication between your browser and our servers is encrypted using TLS. We do not store user passwords; authentication is handled by Clerk, a dedicated identity provider.
2. Infrastructure security
Our application is hosted on Vercel, which provides a secure, serverless global infrastructure. We inherit Vercel's physical security and multi-layered protection against DDoS attacks. This website ships a strict Content-Security-Policy, denies framing, and sets nosniff and referrer policies on every response.
3. External components
- Authentication: powered by Clerk, ensuring secure identity management.
- Analytics and monitoring: industry-standard logging and monitoring tools to ensure uptime and detect anomalies.
- AI employees: act only within the connections and approval rules you configure, and every action is logged.
4. Responsible disclosure
We welcome reports of potential security vulnerabilities. If you discover a security issue, please contact us at iam-security@yozigo.com.
5. Compliance and standards
We maintain a security.txt file for automatic security vulnerability reporting and follow RFC 9116. You can find our security metadata at /.well-known/security.txt.