Security Measures
Last updated: August 2026
This page describes the technical and organizational measures Yachay Systems maintains for the operation of its platform. Where we process personal data on behalf of a customer, the Data Processing Agreement governs that processing and takes precedence over this page.
1. Governance and Personnel
- Written confidentiality obligations for personnel with access to customer personal data
- Role-appropriate security and privacy training
- Access approval and revocation processes based on job responsibilities
- Documented incident response and escalation procedures
2. Access and Identity
- Unique user accounts and role-based access for production systems
- Least-privilege access and periodic review of privileged access
- Multi-factor authentication for privileged administrative access where technically supported
- Secure handling of credentials, API keys, and secrets; passwords stored using one-way hashing
3. Encryption and Transmission
- Encrypted transmission using current TLS for supported web and API connections
- Encryption at rest for production storage volumes and backups containing customer personal data
- Controlled use of secure channels for administrative access and data transfer
4. Application and Infrastructure Security
- Logical separation of customer environments and tenant data
- Security patching and dependency maintenance based on risk
- Input validation, authentication controls, and protection against common web application threats
- Logging and monitoring of relevant production, security, and administrative events
- Malware protection and restricted production access where appropriate to the system
5. Availability and Recovery
- Backups appropriate to the service and to the criticality of the data
- Restricted backup access and protected backup storage
- Documented restoration and continuity procedures with periodic review or testing
- Capacity and availability monitoring for material production services
6. Development and Change Management
- Separation of production access from ordinary development work
- Review and testing appropriate to the risk of material code and configuration changes
- Use of non-production or minimized data for testing where reasonably practicable
- Security review for material new integrations and subprocessors
7. Data Lifecycle
- Data minimization through configurable intake fields and scoped integrations
- Export and deletion processes following termination
- Backup expiration through an ordinary lifecycle targeted within ninety days
- Secure disposal of obsolete storage and credentials through infrastructure provider controls
Hosting and Subprocessors
Primary hosting and infrastructure are provided by Hetzner Online GmbH in Germany. The current list of subprocessors, their locations, and the notice procedure for changes are set out in the Data Processing Agreement.
Scope and Changes
These measures are reviewed as the platform evolves and may be updated, provided the level of protection is not reduced. This page describes our current practice and is not a warranty of a specific outcome; the contractual obligations are those set out in the Terms of Service and the Data Processing Agreement.
Reporting a Vulnerability
If you believe you have found a security issue, please contact us at info@yachay.systems before disclosing it elsewhere. Please do not test the security of our systems without written authorization.
Sicherheitsmaßnahmen
Stand: August 2026
Diese Seite beschreibt die technischen und organisatorischen Maßnahmen, die Yachay Systems für den Betrieb der Plattform vorhält. Soweit wir personenbezogene Daten im Auftrag eines Kunden verarbeiten, gilt für diese Verarbeitung der Auftragsverarbeitungsvertrag; er geht dieser Seite vor.
1. Organisation und Personal
- Schriftliche Vertraulichkeitsverpflichtung für Personen mit Zugriff auf personenbezogene Kundendaten
- Rollengerechte Schulung zu Sicherheit und Datenschutz
- Verfahren zur Erteilung und zum Entzug von Zugriffsrechten anhand der Aufgaben
- Dokumentierte Verfahren für Sicherheitsvorfälle und Eskalation
2. Zugriff und Identität
- Individuelle Benutzerkonten und rollenbasierter Zugriff auf Produktivsysteme
- Zugriff nach dem Prinzip der geringsten Rechte, mit regelmäßiger Überprüfung privilegierter Zugriffe
- Mehrfaktor-Authentifizierung für privilegierte administrative Zugriffe, soweit technisch unterstützt
- Sicherer Umgang mit Zugangsdaten, API-Schlüsseln und Secrets; Passwörter werden als Einweg-Hash gespeichert
3. Verschlüsselung und Übertragung
- Verschlüsselte Übertragung mit aktuellem TLS für unterstützte Web- und API-Verbindungen
- Verschlüsselung im Ruhezustand für Produktivspeicher und Sicherungen mit personenbezogenen Kundendaten
- Kontrollierte Nutzung gesicherter Kanäle für administrativen Zugriff und Datenübertragung
4. Anwendungs- und Infrastruktursicherheit
- Logische Trennung der Kundenumgebungen und Mandantendaten
- Risikoorientiertes Einspielen von Sicherheitsupdates und Pflege von Abhängigkeiten
- Eingabevalidierung, Authentifizierungskontrollen und Schutz gegen verbreitete Angriffe auf Webanwendungen
- Protokollierung und Überwachung relevanter Produktiv-, Sicherheits- und Administrationsereignisse
- Schutz vor Schadsoftware und eingeschränkter Produktivzugriff, soweit für das System angemessen
5. Verfügbarkeit und Wiederherstellung
- Sicherungen, die dem Dienst und der Kritikalität der Daten angemessen sind
- Eingeschränkter Zugriff auf Sicherungen und geschützte Ablage der Sicherungen
- Dokumentierte Wiederherstellungs- und Fortführungsverfahren mit regelmäßiger Überprüfung oder Erprobung
- Überwachung von Kapazität und Verfügbarkeit wesentlicher Produktivdienste
6. Entwicklung und Änderungsmanagement
- Trennung des Produktivzugriffs von der gewöhnlichen Entwicklungsarbeit
- Prüfung und Test entsprechend dem Risiko wesentlicher Code- und Konfigurationsänderungen
- Verwendung von Nicht-Produktiv- oder minimierten Daten für Tests, soweit vernünftigerweise umsetzbar
- Sicherheitsprüfung bei wesentlichen neuen Integrationen und Unterauftragsverarbeitern
7. Datenlebenszyklus
- Datenminimierung durch konfigurierbare Erfassungsfelder und im Umfang begrenzte Integrationen
- Export- und Löschverfahren nach Vertragsende
- Ablauf der Sicherungen im gewöhnlichen Lebenszyklus mit Zielwert innerhalb von neunzig Tagen
- Sichere Entsorgung nicht mehr benötigter Speicher und Zugangsdaten über die Kontrollen des Infrastrukturanbieters
Hosting und Unterauftragsverarbeiter
Hosting und Infrastruktur werden vorrangig von der Hetzner Online GmbH in Deutschland bereitgestellt. Die aktuelle Liste der Unterauftragsverarbeiter, ihre Standorte und das Verfahren zur Ankündigung von Änderungen stehen im Auftragsverarbeitungsvertrag.
Geltungsbereich und Änderungen
Diese Maßnahmen werden mit der Weiterentwicklung der Plattform überprüft und können angepasst werden, sofern das Schutzniveau dadurch nicht sinkt. Die Seite beschreibt die derzeitige Praxis und ist keine Zusicherung eines bestimmten Erfolgs; die vertraglichen Pflichten ergeben sich aus den Allgemeinen Geschäftsbedingungen und dem Auftragsverarbeitungsvertrag.
Meldung von Schwachstellen
Wenn Sie ein Sicherheitsproblem vermuten, wenden Sie sich bitte an info@yachay.systems, bevor Sie es anderweitig offenlegen. Bitte testen Sie unsere Systeme nicht ohne schriftliche Erlaubnis auf Sicherheitslücken.
Medidas de seguridad
Última actualización: agosto de 2026
Esta página describe las medidas técnicas y organizativas que Yachay Systems mantiene para el funcionamiento de su plataforma. Cuando tratamos datos personales por cuenta de un cliente, dicho tratamiento se rige por el Acuerdo de Tratamiento de Datos, que prevalece sobre esta página.
1. Gobernanza y personal
- Obligaciones escritas de confidencialidad para el personal con acceso a datos personales de clientes
- Formación en seguridad y privacidad adecuada al rol
- Procesos de aprobación y revocación de accesos según las responsabilidades del puesto
- Procedimientos documentados de respuesta a incidentes y escalado
2. Acceso e identidad
- Cuentas de usuario individuales y acceso basado en roles para los sistemas de producción
- Acceso con privilegios mínimos y revisión periódica de los accesos privilegiados
- Autenticación multifactor para el acceso administrativo privilegiado cuando esté técnicamente soportada
- Manejo seguro de credenciales, claves de API y secretos; las contraseñas se almacenan mediante hash unidireccional
3. Cifrado y transmisión
- Transmisión cifrada con TLS actual para las conexiones web y de API soportadas
- Cifrado en reposo para los volúmenes de producción y las copias de seguridad que contienen datos personales de clientes
- Uso controlado de canales seguros para el acceso administrativo y la transferencia de datos
4. Seguridad de aplicaciones e infraestructura
- Separación lógica de los entornos de cliente y de los datos por inquilino
- Aplicación de parches de seguridad y mantenimiento de dependencias según el riesgo
- Validación de entradas, controles de autenticación y protección frente a amenazas habituales de aplicaciones web
- Registro y supervisión de eventos relevantes de producción, seguridad y administración
- Protección frente a software malicioso y acceso restringido a producción cuando resulte adecuado para el sistema
5. Disponibilidad y recuperación
- Copias de seguridad adecuadas al servicio y a la criticidad de los datos
- Acceso restringido a las copias de seguridad y almacenamiento protegido de las mismas
- Procedimientos documentados de restauración y continuidad, con revisión o prueba periódica
- Supervisión de capacidad y disponibilidad de los servicios de producción relevantes
6. Desarrollo y gestión de cambios
- Separación del acceso a producción respecto del trabajo ordinario de desarrollo
- Revisión y pruebas acordes al riesgo de los cambios relevantes de código y configuración
- Uso de datos de no producción o minimizados para pruebas cuando sea razonablemente posible
- Revisión de seguridad para nuevas integraciones y subencargados relevantes
7. Ciclo de vida de los datos
- Minimización de datos mediante campos de admisión configurables e integraciones acotadas
- Procesos de exportación y eliminación tras la terminación
- Caducidad de las copias de seguridad en un ciclo ordinario con objetivo dentro de noventa días
- Eliminación segura del almacenamiento y las credenciales obsoletos mediante los controles del proveedor de infraestructura
Alojamiento y subencargados
El alojamiento y la infraestructura principales corren a cargo de Hetzner Online GmbH en Alemania. La lista vigente de subencargados, sus ubicaciones y el procedimiento de notificación de cambios figuran en el Acuerdo de Tratamiento de Datos.
Alcance y cambios
Estas medidas se revisan a medida que evoluciona la plataforma y pueden actualizarse, siempre que no se reduzca el nivel de protección. Esta página describe nuestra práctica actual y no constituye una garantía de un resultado concreto; las obligaciones contractuales son las establecidas en los Términos y Condiciones y en el Acuerdo de Tratamiento de Datos.
Comunicación de vulnerabilidades
Si cree haber encontrado un problema de seguridad, contáctenos en info@yachay.systems antes de divulgarlo en otro lugar. Por favor, no realice pruebas de seguridad sobre nuestros sistemas sin autorización escrita.