Skip to content
Yasmine
Log inStart free

Security & isolation

Every workspace has separate state, credentials, and runtime identity, with additional dedicated compute on Dev.

Tenant-scoped execution

Free and Starter run in separate containers on shared AWS hosts. Runtime identity, encrypted state, and credentials are tenant-scoped. Dev adds dedicated Fargate compute.

Model routes

Included/platform routes use Yasmine credits and pricing. Eligible plans can connect a supported account or key; connected routes are provider-billed with no Yasmine token markup. Selected providers process request content and necessary credentials under their terms.

Encryption

Secrets and configuration are encrypted at rest with per-tenant keys; all transit is TLS. Conversation memory lives on an encrypted, per-tenant volume.

Least privilege

Each tenant's IAM role is scoped to only its own secret and storage. The control plane is tokenless for customer credentials.

Tool policy

Tool calls use each workspace's Allow, Ask, or Block policy. Actions configured as Ask pause for approval; unattended runs deny them.

Responsible disclosure

Found something? Email security@yasmine.works. We publish a security.txt and respond promptly.

SOC 2 Type II is on our roadmap. DPA and transfer-term form and availability remain under counsel review; contact us for current status.