Skip to content
Security · Compliance · Trust

Lock down your delivery pipeline without slowing it.

Yeinz is built on a single-binary, tenant-isolated architecture with SOC 2 Type II, ISO 27001, and 99.99% trailing-twelve-month uptime — so platform teams consolidating tooling don't trade velocity for audit posture.

  • SOC 2Type II attested
  • ISO27001 certified
  • 99.99%Trailing 12-mo uptime
  • 7 minMedian support response
Audited, certified, continuously monitored

Compliance posture, on a single instrument.

  • SOC 2
    SOC 2 Type II Annual audit · latest report dated Q4 2025
  • ISO
    ISO/IEC 27001:2022 Information security management certified
  • GDPR
    GDPR & UK GDPR DPA available · EU/UK SCCs incorporated
  • HIPAA
    HIPAA · BAA Business Associate Agreement on request
Architecture

One binary. Tenant-isolated by default. Encrypted everywhere data lives.

Yeinz runs as a single static binary under 38MB. Each customer workload executes inside a logically isolated sandbox; cross-tenant data paths do not exist. Metadata is encrypted at rest with envelope keys rotated every 90 days, and every byte that leaves your VPC is wrapped in TLS 1.3 with forward secrecy.

  • AES-256 at rest Per-tenant envelope keys, KMS-backed, 90-day rotation.
  • TLS 1.3 in transit Strict ciphers, HSTS, certificate pinning on the CLI.
  • Tenant isolation Namespaced processes, dedicated signing keys, no shared execution pools.
  • BYOK & residency Bring-your-own-key on Enterprise; choose US, EU, or AU data residency.
Frameworks & attestations

Procurement-ready language. Audit dates attached.

Every framework below is supported by a current attestation or signed agreement — not a roadmap item. Reports are available under NDA through your account team.

  1. 01

    SOC 2 Type II

    Continuous controls monitoring with annual independent audit covering Security, Availability, and Confidentiality trust criteria.

    Last attested · 14 Nov 2025 · auditor: Coalfire ISAO
  2. 02

    ISO/IEC 27001:2022

    Certified Information Security Management System with a scoped Statement of Applicability covering 93 Annex A controls.

    Certificate issued · 02 Sep 2025 · valid through Sep 2028
  3. 03

    GDPR · UK GDPR

    Data Processing Agreement, EU and UK Standard Contractual Clauses, and a documented data-subject request workflow with 30-day SLA.

    DPA template · v4.1 · signed by 1,200+ customers
  4. 04

    HIPAA · CCPA

    Business Associate Agreement available for healthcare workloads; CCPA-aligned data subject access and deletion API live in all regions.

    BAA on request · CCPA API GA since Mar 2024
Sub-processors & data residency

Who touches your data, and where it physically lives.

Yeinz works with a deliberately small set of sub-processors — only the infrastructure providers required to run a globally available platform. Each is bound by a written agreement that meets GDPR Article 28, and a current list is published below. Customers on Enterprise plans can pin storage and compute to a single region.

Current sub-processors

ProviderPurposeData categoriesRegion
Amazon Web ServicesPrimary compute & object storageBuild artifacts, logs, telemetry metadataUS-East · EU-West · AU-Southeast
CloudflareEdge network, DDoS protection, TLS terminationRequest metadata, IP (transient)Global anycast
Datadog (US)Internal platform observabilityOperational metrics (no customer payload)US-East
StripeBilling & subscription managementBilling contact, last four card digitsUS
ZendeskCustomer support ticketingSupport correspondence, attachments you sendUS · EU

A live sub-processor list, with 30-day change-notice subscription, is available at /security/#subprocessors. We notify customers in writing before any new sub-processor is engaged.

Data residency options

  • United StatesDefault region · US-East, US-West replicas
  • European UnionEU-West primary · GDPR + SCCs · available on all plans
  • Australia & APACAU-Southeast primary · for AU/NZ regulated workloads
Operational security posture

Numbers a CISO can paste into a board deck.

99.99% Platform uptime Trailing 12 months · public status page
11 min Mean incident response Security events · P0–P2 · 2025 YTD
7 min Support first response Median · 24×7 on-call · all severity tiers
41 Countries served 2,400+ engineering teams in production