Lock down your delivery pipeline without slowing it.
Yeinz is built on a single-binary, tenant-isolated architecture with SOC 2 Type II, ISO 27001, and 99.99% trailing-twelve-month uptime — so platform teams consolidating tooling don't trade velocity for audit posture.
- SOC 2Type II attested
- ISO27001 certified
- 99.99%Trailing 12-mo uptime
- 7 minMedian support response
Compliance posture, on a single instrument.
-
SOC 2
SOC 2 Type II Annual audit · latest report dated Q4 2025
-
ISO
ISO/IEC 27001:2022 Information security management certified
-
GDPR
GDPR & UK GDPR DPA available · EU/UK SCCs incorporated
-
HIPAA
HIPAA · BAA Business Associate Agreement on request
One binary. Tenant-isolated by default. Encrypted everywhere data lives.
Yeinz runs as a single static binary under 38MB. Each customer workload executes inside a logically isolated sandbox; cross-tenant data paths do not exist. Metadata is encrypted at rest with envelope keys rotated every 90 days, and every byte that leaves your VPC is wrapped in TLS 1.3 with forward secrecy.
- AES-256 at rest Per-tenant envelope keys, KMS-backed, 90-day rotation.
- TLS 1.3 in transit Strict ciphers, HSTS, certificate pinning on the CLI.
- Tenant isolation Namespaced processes, dedicated signing keys, no shared execution pools.
- BYOK & residency Bring-your-own-key on Enterprise; choose US, EU, or AU data residency.
Procurement-ready language. Audit dates attached.
Every framework below is supported by a current attestation or signed agreement — not a roadmap item. Reports are available under NDA through your account team.
-
01
SOC 2 Type II
Continuous controls monitoring with annual independent audit covering Security, Availability, and Confidentiality trust criteria.
-
02
ISO/IEC 27001:2022
Certified Information Security Management System with a scoped Statement of Applicability covering 93 Annex A controls.
-
03
GDPR · UK GDPR
Data Processing Agreement, EU and UK Standard Contractual Clauses, and a documented data-subject request workflow with 30-day SLA.
-
04
HIPAA · CCPA
Business Associate Agreement available for healthcare workloads; CCPA-aligned data subject access and deletion API live in all regions.
Who touches your data, and where it physically lives.
Yeinz works with a deliberately small set of sub-processors — only the infrastructure providers required to run a globally available platform. Each is bound by a written agreement that meets GDPR Article 28, and a current list is published below. Customers on Enterprise plans can pin storage and compute to a single region.
Current sub-processors
| Provider | Purpose | Data categories | Region |
|---|---|---|---|
| Amazon Web Services | Primary compute & object storage | Build artifacts, logs, telemetry metadata | US-East · EU-West · AU-Southeast |
| Cloudflare | Edge network, DDoS protection, TLS termination | Request metadata, IP (transient) | Global anycast |
| Datadog (US) | Internal platform observability | Operational metrics (no customer payload) | US-East |
| Stripe | Billing & subscription management | Billing contact, last four card digits | US |
| Zendesk | Customer support ticketing | Support correspondence, attachments you send | US · EU |
A live sub-processor list, with 30-day change-notice subscription, is available at /security/#subprocessors. We notify customers in writing before any new sub-processor is engaged.
Data residency options
- United StatesDefault region · US-East, US-West replicas
- European UnionEU-West primary · GDPR + SCCs · available on all plans
- Australia & APACAU-Southeast primary · for AU/NZ regulated workloads