Security & isolation
Every workspace has separate state, credentials, and runtime identity, with additional dedicated compute on Dev.
Tenant-scoped execution
Free and Starter run in separate containers on shared AWS hosts. Runtime identity, encrypted state, and credentials are tenant-scoped. Dev adds dedicated Fargate compute.
Model routes
Included/platform routes use Yasmine credits and pricing. Eligible plans can connect a supported account or key; connected routes are provider-billed with no Yasmine token markup. Selected providers process request content and necessary credentials under their terms.
Encryption
Secrets and configuration are encrypted at rest with per-tenant keys; all transit is TLS. Conversation memory lives on an encrypted, per-tenant volume.
Least privilege
Each tenant's IAM role is scoped to only its own secret and storage. The control plane is tokenless for customer credentials.
Tool policy
Tool calls use each workspace's Allow, Ask, or Block policy. Actions configured as Ask pause for approval; unattended runs deny them.
Responsible disclosure
Found something? Email security@yasmine.works. We publish a security.txt and respond promptly.
SOC 2 Type II is on our roadmap. DPA and transfer-term form and availability remain under counsel review; contact us for current status.