Your work stays yours.

Yondervast is built for client work. Here is how we protect the ideas, the assets and the people inside every project.

Access And Identity

Two-factor authentication (TOTP), signed trusted devices and role-based access on every workspace and project. Underneath the API, Row-Level Security guards every table: no client can read another team's rows.

Data Protection

Everything travels over TLS and rests encrypted (AES-256) in the database and in object storage. Magic links are single-use, share tokens are unguessable and media URLs are signed and short-lived.

Infrastructure

Yondervast runs on managed infrastructure: Vercel for the application, Supabase for the database and authentication, Cloudflare R2 for media. Preview and production stay strictly separated.

Development Discipline

Every change ships through review and a CI gate that enforces the house design and security contracts. Database migrations are additive and applied through a controlled channel.

Security Reviews

Recurring internal security audits with tracked findings, and fixes that ship in days, not quarters. Recent hardening covered invite flows, single-use tokens and rate limits on anonymous endpoints.

Incident Response

Anything suspicious reaches a human fast. Write to hello@yondervast.ai and a founder reads it the same day.

Subprocessors

The services that touch project data. Model providers process prompts and references only to produce your output.

AnthropicCloudflare R2Google GeminiOpenAIPerplexityResendSupabaseUpstashVercel

Data Retention

Your content lives in your workspace for as long as you keep it. Delete an asset or a project and it disappears from the product. For full account deletion, write to us and we handle it promptly.