YAJU AS stores your API keys and runs your AI agents, so security is part of the product, not an extra. This page explains in plain language what we do today to protect the Platform and your data, what happens if something goes wrong, and what we expect from you.
No system is completely secure, and no company can promise that an incident will never happen. What we can do is apply reasonable measures, keep access to data restricted, react quickly when something goes wrong and be transparent with you. That is the approach described on this page.
Our approach
Our security approach is based on a few simple principles:
- Least access: only the people and systems that need access to data should have it.
- Encryption: sensitive data, such as API keys and Agent Data, is stored encrypted.
- Customer control: each workspace decides who can access its agents and with which permissions.
- Shared responsibility: we protect the Platform, and you protect your Account, your keys and the way you configure your agents.
- Transparency: if an incident affects your data, we tell you.
What we do
- API keys and credentials: stored encrypted in secure vaults (AWS Secrets Manager) and used only to run the agents and features you enable.
- Encrypted data: conversations, logs and operational data are stored encrypted in our database hosted by Neon in Frankfurt, Germany.
- Restricted access: inside CAP, only our founder and CEO can access customer data, and only for the purposes listed in our Privacy Policy.
- Workspace control: each workspace Owner decides who has access and with which role and permissions.
- Limits per plan: the number of agents and sandboxes is limited by your plan.
- Payments: handled by Stripe. We do not store your full card details.
- Trusted providers: we rely on established infrastructure providers (Neon, Vercel, Cloudflare, AWS and Stripe) for hosting, storage, secrets and payments.
If something goes wrong
If a security incident affects your data, our founder and CEO leads the response. In general terms, the response includes:
- Containing the incident to limit its impact.
- Investigating what happened and which data or accounts were affected.
- Informing affected users by email and in the Platform without undue delay.
- Notifying the data protection authority within 72 hours when the law requires it.
- Fixing the cause and taking steps to prevent it from happening again.
Shared responsibility
Security depends on both of us. CAP is responsible for the security of the Platform and of the data it stores. You are responsible for the security of your Account, of your API keys at your providers, and of the way you configure your agents, their permissions and their autonomy.
What you can do
- Use API keys with minimum permissions and set spending limits at your AI provider.
- Rotate your keys regularly and delete the ones you no longer use.
- Give workspace members only the permissions they need, and review them from time to time.
- Remove members who no longer need access to your workspace.
- Protect your Google, GitHub or YAJU AS login.
- Give your agents only the autonomy their tasks need, and review what they do.
- Tell us at once if you see anything suspicious: contact@capconsultor.eu.
More information
We will publish more details about our security measures as the Platform grows. For how we handle personal data, see our Privacy Policy and Data Commitments.
Found a vulnerability?
Please follow our Responsible Disclosure Policy. We appreciate the help of anyone who reports a problem responsibly.