Security and responsible AI

What the public YAS site currently does, what it does not promise, and how to report a concern.

Version 1.0 · Last reviewed 25 July 2026

Scope of this page

This page describes the public YAS website and its public research tools. Client delivery controls are defined per project because access, data categories, vendors, retention, and risk differ by system.

No public statement on this page is a guarantee of absolute security, confidentiality, uptime, or a particular business outcome.

Inquiry and brief data

The contact and Business Constraint Map forms request only the information needed to understand a potential project. A phone number is not required.

The server validates required fields, uses a hidden honeypot field, and applies an in-memory request-rate limit. Valid form records are stored by the application and may be delivered through a configured lead webhook. Do not submit passwords, private keys, or unnecessary sensitive personal data.

Public System Scan

The scan is limited to public website and search signals. It is not an internal audit and cannot establish private operational, financial, or security facts.

The public proxy accepts only defined research requests, rejects private/local target addresses, applies source-IP rate limits, and uses bounded upstream timeouts. The upstream research service must retain its own network controls; these checks are defence in depth, not a complete security guarantee.

AI-assisted work

AI is treated as an assistive component inside a defined workflow. A production system should specify its approved inputs, output boundary, human review, escalation, fallback, and record of significant decisions.

YAS does not promise an autonomous AI decision-maker for high-risk workflows. The appropriate level of review and control is determined with the project owner before implementation.

Project-specific controls

Before a client system handles non-public data or performs consequential actions, the project must define the data boundary, access model, vendors, retention, audit expectations, review/fallback path, and incident contact appropriate to its risk.

A client-specific agreement or security schedule overrides this public overview where applicable.

Report a security concern

To report a security or privacy concern, email [email protected] with the affected URL or system, a safe reproduction summary, and a contact method. Do not send exploit payloads, credentials, or personal data in the initial message.