Security & trust

Built to be trusted with your AI.

Yardstick sits close to how your agents work and what they cost. Here is how we protect that data today, and where we are headed.

Measure outcomes, not secrets

Yardstick scores verified outcomes and cost from agent metadata. We avoid ingesting your source code or customer data wherever the measurement doesn't require it, and we collect the minimum we need.

Encrypted in transit and at rest

All traffic is served over TLS. Data is encrypted at rest in a managed, access-controlled database, and secrets live in encrypted configuration, never in source control.

Least-privilege access

Connect what you want measured through scoped OAuth or narrowly-scoped tokens, not broad credentials. Grant only the read access a tool needs, and revoke it any time.

EU data residency

Primary data is stored in the European Union on managed infrastructure. We keep the data footprint small and regional by default.

Tenant isolation

Each organization's data is logically separated and scoped to its own account. One customer's agents, budgets, and outcomes are never visible to another.

Auditable by design

Yardstick is a measurement tool, so traceability is the point. Treasury's Audit keeps an append-only record of spend, allowances, and decisions, with a complete owner and approval chain.

How we operate

We don't run our own hardware. Yardstick is built on established cloud providers with mature security programs, and we keep our own practices tight:

  • Managed, encrypted infrastructure. Providers with strong security track records, not hardware we run ourselves.
  • Separated environments. Production data is isolated from development and testing.
  • Encrypted backups. Regular backups with recovery, encrypted at rest.
  • Monitored. Backend errors and anomalies are tracked and alerted on.

Compliance & privacy

We're early, and we're building security and compliance in from the start rather than bolting it on later.

  • SOC 2 Type II. On our roadmap. We're aligning controls now so the audit is a formality, not a scramble.
  • GDPR & CCPA. We honor data-subject requests under both, keep what we collect minimal, and never sell your data.
  • Data processing agreement. A DPA is available to customers and design partners on request.
  • Sub-processors. A current list is available to design partners and customers on request.
  • Data deletion. Ask and we remove your data. Waitlist contacts can one-click unsubscribe and be purged.

Responsible disclosure

Found a vulnerability? Email security@yardstick.fi with the details. We aim to acknowledge within two business days and will keep you posted on the fix. Please give us a reasonable window to remediate before any public disclosure.

Yardstick · Security