How Yoraito protects the close.
Finance teams need more than a security badge. They need to understand where data moves, what controls the workflow, and who remains accountable for the result.
Automation with a visible chain of custody.
Yoraito is designed around a simple principle: financial work should be explainable from the source system through execution, exception handling, and human review.
The controls finance teams ask about first.
The current platform is built on managed infrastructure and explicit service boundaries. These are the technical foundations of the product.
Encrypted in transit
Production traffic uses HTTPS/TLS between users, services, and connected systems.
Railway-hosted services
Application services and managed data services run on Railway infrastructure.
PostgreSQL-backed records
Core application records are stored in PostgreSQL-backed services.
OpenRouter model routing
Model calls route through OpenRouter using configured zero-data-retention models.
Scoped service credentials
Services use environment-managed credentials and internal service boundaries.
Human review stays visible
The close is designed to route exceptions to people rather than silently post uncertain work.
Compliance posture
Where we are today, what we ship, and what we're working toward.
SOC 2 Type II
Auditor engaged Q3 2026. Type I expected Q4 2026; Type II expected Q1 2027. Expected: Q1 2027
GDPR
DPA template available on request. Sub-processor list below. Expected: Live since 2024
CCPA
Privacy policy + data-deletion workflow. Expected: Live since 2024
ISO 42001 (AI Management Systems)
Readiness review on Q1 2027 roadmap. We do not claim certification until we have one. Expected: Q1 2027 review
HIPAA
Not in scope. We do not handle PHI today. Contact us before signing if your workload requires HIPAA. Expected: n/a
FedRAMP
Not authorized today. No government-cloud deployment. Expected: n/a
Sub-processors
The services supporting the platform and their stated compliance posture.
| Sub-processor | Purpose | Their compliance |
|---|---|---|
| Neon | Postgres hosting | SOC 2 Type II |
| Cloudflare | R2 object storage + CDN | SOC 2 Type II |
| Auth0 | Authentication | SOC 2 Type II, ISO 27001, ISO 27018 |
| Railway | Application hosting | SOC 2 Type II |
| OpenRouter | LLM routing | SOC 2 Type II |
| Sentry | Application monitoring | SOC 2 Type II |
| Resend | Transactional email | SOC 2 Type II |
What happens to a close input.
The architecture follows the same path a reviewer follows: source, controlled execution, exception handling, and approval.
Connect
Data enters from connected finance systems or uploaded files.
Execute
Structured workflows and model-assisted operations run inside the platform.
Review
Exceptions and decisions remain visible to the finance team.
Trace
The result carries the context needed to understand how it was produced.
Self-serve resources
Architecture, security, sales, and reliability materials.
Contact
Questions about security, privacy, DPA/legal, or procurement.
Talk through the trust model.
Contact the team for the current technical information available for evaluation.