Security
How Yolias protects your account, your workspace and the data you discover.
Sign-in without passwords
Yolias uses email sign-in links or Google instead of passwords, so there is no password to reuse, phish or leak. Each link works once and expires after one hour. You can add two-factor authentication with an authenticator app, and from Settings → Account sign out of every device at once.
Workspace isolation
Every search, campaign, company and prospect belongs to a workspace. Database row-level security rules allow access only to members of that workspace, and they are enforced by the database itself, not only by the app.
Roles
- Owner — manages the plan and the team.
- Admin — invites and removes members, manages the plan.
- Member — works with searches, campaigns and prospects.
Data protection
- All traffic to Yolias is encrypted in transit with TLS.
- Data is stored with our database provider, encrypted at rest.
- Privileged keys are used only on the server and never reach the browser.
- Files attached to a search are read to understand it and are not stored.
- Card details are entered on the payment provider’s page and never reach Yolias.
- Errors are monitored to fix them quickly; reports are stripped of personal details and secrets.
AI requests
Searches are sent to our AI provider only to produce your customer profile. We send the minimum needed: the request, its attachments and your business context.
Deleting data
Deleting your account removes your profile, and when you are the workspace’s only member, all of its discovery data. Searches can be deleted individually from the sidebar.
Reporting a vulnerability
If you believe you have found a security issue, please report it through the Contact page with the topic “Product support” and include steps to reproduce it. Please do not access other users’ data or disrupt the service while testing.