Your work stays yours.
Yondervast is built for client work. Here is how we protect the ideas, the assets and the people inside every project.
Access And Identity
Two-factor authentication (TOTP), signed trusted devices and role-based access on every workspace and project. Underneath the API, Row-Level Security guards every table: no client can read another team's rows.
Data Protection
Everything travels over TLS and rests encrypted (AES-256) in the database and in object storage. Magic links are single-use, share tokens are unguessable and media URLs are signed and short-lived.
Infrastructure
Yondervast runs on managed infrastructure: Vercel for the application, Supabase for the database and authentication, Cloudflare R2 for media. Preview and production stay strictly separated.
Development Discipline
Every change ships through review and a CI gate that enforces the house design and security contracts. Database migrations are additive and applied through a controlled channel.
Security Reviews
Recurring internal security audits with tracked findings, and fixes that ship in days, not quarters. Recent hardening covered invite flows, single-use tokens and rate limits on anonymous endpoints.
Incident Response
Anything suspicious reaches a human fast. Write to hello@yondervast.ai and a founder reads it the same day.
Subprocessors
The services that touch project data. Model providers process prompts and references only to produce your output.
Data Retention
Your content lives in your workspace for as long as you keep it. Delete an asset or a project and it disappears from the product. For full account deletion, write to us and we handle it promptly.