TRUST CENTER

How Yoraito protects the close.

Finance teams need more than a security badge. They need to understand where data moves, what controls the workflow, and who remains accountable for the result.

CONTROL MAP
Source
Run
Review
A trace behind the outcomeEvery stage remains visible to the people accountable for the close.
THE CONTROL PROMISE

Automation with a visible chain of custody.

Yoraito is designed around a simple principle: financial work should be explainable from the source system through execution, exception handling, and human review.

Controller-checkedSource / run / review
EVIDENCE WALL

The controls finance teams ask about first.

The current platform is built on managed infrastructure and explicit service boundaries. These are the technical foundations of the product.

Encrypted in transit

Production traffic uses HTTPS/TLS between users, services, and connected systems.

Railway-hosted services

Application services and managed data services run on Railway infrastructure.

PostgreSQL-backed records

Core application records are stored in PostgreSQL-backed services.

OpenRouter model routing

Model calls route through OpenRouter using configured zero-data-retention models.

Scoped service credentials

Services use environment-managed credentials and internal service boundaries.

Human review stays visible

The close is designed to route exceptions to people rather than silently post uncertain work.

COMPLIANCE POSTURE

Compliance posture

Where we are today, what we ship, and what we're working toward.

SOC 2 Type II

Auditor engaged Q3 2026. Type I expected Q4 2026; Type II expected Q1 2027. Expected: Q1 2027

In progress

GDPR

DPA template available on request. Sub-processor list below. Expected: Live since 2024

Live

CCPA

Privacy policy + data-deletion workflow. Expected: Live since 2024

Live

ISO 42001 (AI Management Systems)

Readiness review on Q1 2027 roadmap. We do not claim certification until we have one. Expected: Q1 2027 review

In progress

HIPAA

Not in scope. We do not handle PHI today. Contact us before signing if your workload requires HIPAA. Expected: n/a

Not in scope

FedRAMP

Not authorized today. No government-cloud deployment. Expected: n/a

Not in scope
SUB-PROCESSORS

Sub-processors

The services supporting the platform and their stated compliance posture.

Sub-processorPurposeTheir compliance
NeonPostgres hostingSOC 2 Type II
CloudflareR2 object storage + CDNSOC 2 Type II
Auth0AuthenticationSOC 2 Type II, ISO 27001, ISO 27018
RailwayApplication hostingSOC 2 Type II
OpenRouterLLM routingSOC 2 Type II
SentryApplication monitoringSOC 2 Type II
ResendTransactional emailSOC 2 Type II
DATA FLOW

What happens to a close input.

The architecture follows the same path a reviewer follows: source, controlled execution, exception handling, and approval.

01

Connect

Data enters from connected finance systems or uploaded files.

02

Execute

Structured workflows and model-assisted operations run inside the platform.

03

Review

Exceptions and decisions remain visible to the finance team.

04

Trace

The result carries the context needed to understand how it was produced.

SELF-SERVE RESOURCES

Self-serve resources

Architecture, security, sales, and reliability materials.

Security questionnaire responseSecurity questionnaire response.
Agent architectureAgent architecture and tool boundaries.
Multi-ERP architectureMulti-ERP data flow and integration surface.
Sales one-pagerWhat Yoraito does, our design approach, and three ways we differ.
Outcome-pricing trialOutcome-based pricing and QA methodology.
Reliability / QA benchmarkReliability and QA methodology.
CONTACT

Contact

Questions about security, privacy, DPA/legal, or procurement.

EARLY ACCESS

Talk through the trust model.

Contact the team for the current technical information available for evaluation.

Contact Yoraito