Security

How Yolias protects your account, your workspace and the data you discover.

Last updated October 7, 2026

Sign-in without passwords

Yolias uses email sign-in links or Google instead of passwords, so there is no password to reuse, phish or leak. Each link works once and expires after one hour. You can add two-factor authentication with an authenticator app, and from Settings → Account sign out of every device at once.

Workspace isolation

Every search, campaign, company and prospect belongs to a workspace. Database row-level security rules allow access only to members of that workspace, and they are enforced by the database itself, not only by the app.

Roles

  • Owner — manages the plan and the team.
  • Admin — invites and removes members, manages the plan.
  • Member — works with searches, campaigns and prospects.

Data protection

  • All traffic to Yolias is encrypted in transit with TLS.
  • Data is stored with our database provider, encrypted at rest.
  • Privileged keys are used only on the server and never reach the browser.
  • Files attached to a search are read to understand it and are not stored.
  • Card details are entered on the payment provider’s page and never reach Yolias.
  • Errors are monitored to fix them quickly; reports are stripped of personal details and secrets.

AI requests

Searches are sent to our AI provider only to produce your customer profile. We send the minimum needed: the request, its attachments and your business context.

Deleting data

Deleting your account removes your profile, and when you are the workspace’s only member, all of its discovery data. Searches can be deleted individually from the sidebar.

Reporting a vulnerability

If you believe you have found a security issue, please report it through the Contact page with the topic “Product support” and include steps to reproduce it. Please do not access other users’ data or disrupt the service while testing.