Skip to main content

    SOC 2 Report

    Report Period: January 1, 2024 - December 31, 2024
    •SOC 2 Type 2

    SOC 2 Type 2 Certified

    yno.ai has successfully completed a SOC 2 Type 2 examination, demonstrating our commitment to maintaining the highest standards of security, availability, processing integrity, confidentiality, and privacy for our AI platform and customer data.

    1. About SOC 2

    Service Organization Control (SOC) 2 is an auditing procedure that ensures service providers securely manage data to protect the interests of the organization and the privacy of its clients. SOC 2 compliance is particularly important for technology and cloud computing companies like yno.ai.

    SOC 2 Type 2 vs Type 1

    SOC 2 Type 1

    Evaluates the design of security controls at a specific point in time.

    SOC 2 Type 2 ✓

    Evaluates both the design and operating effectiveness of controls over a period of time (typically 6-12 months).

    2. Trust Service Criteria

    Our SOC 2 Type 2 examination covers all five Trust Service Criteria, demonstrating comprehensive security and operational controls:

    Security

    Protection of system resources against unauthorized access, use, disclosure, disruption, modification, or destruction.

    • Multi-factor authentication and access controls
    • Network security and firewall management
    • Vulnerability management and penetration testing
    • Security incident response procedures

    Availability

    System availability for operation and use as committed or agreed upon.

    • 99.9% uptime SLA with monitoring and alerting
    • Redundant infrastructure and failover procedures
    • Disaster recovery and business continuity planning
    • Performance monitoring and capacity management

    Processing Integrity

    System processing is complete, valid, accurate, timely, and authorized.

    • Data validation and error handling procedures
    • AI model accuracy and bias monitoring
    • Transaction processing controls
    • Data integrity verification mechanisms

    Confidentiality

    Information designated as confidential is protected as committed or agreed upon.

    • AES-256 encryption for data at rest and in transit
    • Confidentiality agreements with employees and vendors
    • Data classification and handling procedures
    • Secure data disposal and destruction

    Privacy

    Personal information is collected, used, retained, disclosed, and disposed of in conformity with privacy commitments.

    • GDPR and CCPA compliance programs
    • Privacy by design implementation
    • Data subject rights management
    • Privacy impact assessments

    3. Audit Details

    Examination Overview

    Audit Firm: [Independent CPA Firm]

    Report Type: SOC 2 Type 2

    Service Organization: yno.ai

    Examination Period: January 1, 2024 - December 31, 2024

    Report Date: January 15, 2025

    Opinion: Unqualified (Clean)

    Services Covered

    • AI Platform Services (yno.ai web application and API)
    • Data Processing and Storage Services
    • AI Model Hosting and Inference Services
    • Customer Support and Account Management
    • Security Monitoring and Incident Response

    Key Findings

    ✓ No Material Weaknesses Identified

    The independent auditor found that yno.ai's controls were suitably designed and operating effectively throughout the examination period to meet the applicable trust service criteria.

    4. Security Controls Highlights

    Technical Controls

    • Multi-factor authentication for all user accounts
    • Role-based access controls and least privilege principles
    • End-to-end encryption for data in transit and at rest
    • Automated vulnerability scanning and patch management
    • 24/7 security monitoring and incident response

    Operational Controls

    • Comprehensive security awareness training program
    • Regular security risk assessments and reviews
    • Vendor risk management and due diligence
    • Business continuity and disaster recovery planning
    • Change management and configuration controls

    5. Compliance and Certifications

    In addition to SOC 2 Type 2, yno.ai maintains compliance with multiple industry standards and regulations:

    GDPR

    General Data Protection Regulation

    CCPA

    California Consumer Privacy Act

    ISO 27001

    Information Security Management

    6. Continuous Monitoring

    SOC 2 compliance is not a one-time achievement but an ongoing commitment. We maintain continuous monitoring and improvement of our security controls:

    • Quarterly Internal Audits: Regular assessment of control effectiveness
    • Annual SOC 2 Examinations: Independent third-party validation
    • Continuous Security Monitoring: Real-time threat detection and response
    • Regular Penetration Testing: External security assessments
    • Control Updates: Adaptation to emerging threats and regulatory changes

    7. For Enterprise Customers

    SOC 2 Report Access

    Enterprise customers can request access to our complete SOC 2 Type 2 report under a Non-Disclosure Agreement (NDA). The report provides detailed information about our controls and the auditor's testing procedures.

    Note: SOC 2 reports contain sensitive information about our security controls and are only shared with legitimate business prospects and customers under appropriate confidentiality agreements.

    8. Contact Information

    For questions about our SOC 2 compliance, security controls, or to request access to our SOC 2 report:

    Security Team: [email protected]
    Compliance Team: [email protected]
    Enterprise Sales: [email protected]
    Address: yno.ai Security Team, 160 Robinson Road, #14-04, Singapore