Security

Yohanun's security model starts from an unusual place: access control is a core product feature, not a perimeter bolted on afterwards. This page describes what we do, and only what we actually do.

Last updated: July 4, 2026

Our Approach

Most AI products enforce data boundaries by instructing the model. Yohanun enforces them in the platform: access decisions are made deterministically inside the retrieval query, before any model is called. The model cannot leak data it never received. This is the same mechanism we sell, and it protects every tenant on the platform.

1. Platform-Enforced Access Control

All data is scoped to a tenant at the API layer; cross-tenant access is structurally impossible through the query path, not merely forbidden by policy.

Within a tenant, labeled memory is walled by clearances, classification levels, ownership, and conflict-of-interest checks. Grants and revocations are ledger entries that take effect on the next request.

2. Audit Trails

Every gated read is recorded in an append-only audit log: who asked, what was returned, and under which authority. Agent actions and permission escalations are audited the same way.

Audit records are never rewritten; corrections are recorded as new entries.

3. Encryption & Infrastructure

All traffic is encrypted in transit with TLS. Our cloud infrastructure is hosted in the European Union.

Our standard deployment for regulated customers is a single-tenant instance we operate in the region you choose, the United Kingdom included; nothing of yours touches a shared instance. Where your policy requires it, Yohanun can be self-hosted entirely on your own infrastructure, with a support and update arrangement agreed separately, and can run your own locally served model so that not even a query leaves your control. See deployment options.

4. Authentication & Keys

API access is authenticated with scoped API keys that can be rotated and revoked. Provider API keys you bring (OpenAI, Anthropic, Google, DeepSeek, Mistral) are stored for your tenant only and never shared across tenants.

Identity can be verified rather than asserted: a tenant can require every request to carry a token signed by its own identity provider. The person asking is the token's subject, never what the application claimed, and the audit row records which it was.

5. Retention & Erasure

Nothing is destroyed in ordinary operation. Memory is retired by lifecycle close or supersession, stays readable by identifier, and leaves an append-only trail, so the record is always complete.

When a client, a retention policy or data-protection law requires destruction, a governed purge does it properly: the target (one memory, one document, or one person's material) is resolved to a plan that contains no content; a mandate or a human approval authorises exactly that plan, once; the material is destroyed across every store; and each erased memory leaves a tombstone recording who authorised it and why. The operator fulfilling an erasure request never has to read what they are erasing.

In plain English: destroy it, and prove you did. Both halves, with a receipt.

6. Incident Response

If a breach affecting personal data occurs, we will notify affected customers and the supervisory authority within 72 hours, as required by GDPR.

7. Compliance Posture

Yohanun is operated by GestureLoop Ltd., an Irish company, and is subject to GDPR and the Irish Data Protection Act. Data Processing Agreements are available for customers who require them.

We don't lead with certification badges. A certification attests that a process was followed, on a sampled basis, once a year; our enforcement is deterministic and self-evidencing on every request: access decided by the platform before generation, a per-read audit ledger, governed erasure with a receipt, and self-hosting where policy requires it. That's a stronger claim than a badge, and we invite your security team to challenge it directly: we'll walk through the architecture, the ledgers, and live enforcement in as much depth as they want.

Security Contact

For security inquiries or vulnerability reports:

Email: security@yohanun.com