Security50 permissions170 test files
Written for the person your buyer forwards this to.
Isolation between customers is isolation between deployments, which is the strongest form of it. Everything below is a property of the running product, and where a control depends on configuration this page says so rather than glossing it.
Supply Nation Certified
Delivered by Yuma IT, an Indigenous-led business verified for supplier diversity procurement.
Australian hosted & managed
Yuma IT stands up and supports each deployment onshore. Where the data lives is a design choice, not a region toggle.
Single-tenant
One organisation per deployment. One dedicated database. No shared multi-tenant tenancy and no workspace switch.
Human approval on consequence
Destructive agent actions queue or block. There is no environment variable that switches the gate off.
Security and sovereignty
Where the data actually sits.
One deployment serves one organisation. Application tables carry no organisation or workspace column, which is also why there is no workspace switching to get wrong. Yuma IT hosts and manages deployments in Australia by default; customer-controlled infrastructure remains an option.
Application data
All of it lives in your own database on customer-controlled or Australian-hosted infrastructure. The application and the database are separate components of one dedicated deployment.
Australian hosting
When Yuma IT operates the deployment, application data and agent history sit onshore in Australia under our management. Residency is the commercial model, not a multi-region marketing toggle on a shared tenancy.
Uploaded files
Wherever you point the storage driver: local disk, S3, Cloudflare R2 or Azure Blob. File residency is your decision, not a vendor default.
Chat history
Agent memory and message bodies are stored separately from application tables on purpose, so a routine schema upgrade can never drop conversation history.
Egress
Data leaves the deployment only towards services you configure: your model provider, your email and SMS providers, Xero, Buffer, Slack or Teams, and the feeds you asked it to monitor. Nothing else has an address to send to.
Operator identity
Yuma IT (Supply Nation Certified, Canberra) implements, backs up, and supports the deployment. Publisher credentials and product security controls are stated separately; neither stands in for the other.
Authentication.
Passwords are the floor, not the design.
Sessions
Email and password sign-in. Self-registration is switched off for a deployed-per-client install, because the product is installed for a known organisation rather than joined.
Single sign-on
Microsoft Entra ID, with Entra group to role mapping and a synced user link. Needs an app registration in your tenant.
Two-factor
TOTP with backup codes. Enabling writes an unverified factor and only a successful code activates it, so nobody locks themselves out against a secret they never typed correctly.
Passkeys
WebAuthn with the relying-party ID pinned in code rather than derived. Passkeys are refused, with a stated reason, on an IP-literal or plain-HTTP origin rather than bound to a name that will break.
MFA recovery
Destruction and re-enrolment only. Second factors and backup codes are encrypted at rest, so no operator can read a code back out.
Admin reset
Clearing somebody's second factor revokes their live sessions and is audited under the administrator's name. It sits behind its own permission, not behind user administration, because after a reset the account is reachable with a password alone.
Provisioning
SCIM 2.0 Users and Groups with bearer tokens, discovery, filtering, and separate rate limits for requests and authentication failures.
Machine access
A single API key compared in constant time, or a browser session. Both resolve to a real person's permissions.
Authorisation is fifty reasoned splits, not three tiers.
Approving an agent action is separate from managing agents. Promoting an estimate to a quote is separate from editing estimates. Each split carries the argument for why it exists.
tier baseline + assigned roles + grants - denies
Denies are applied last. Custom roles, per-person grants and per-person denies are database-backed and resolved at request time, not baked into a session.
Repairable
The admin tier holds every action unconditionally and cannot be denied one, so a broken permission row can always be fixed from inside the product.
Fails to the matrix
An unreadable permission table falls back to the static tier matrix. Never to everything, and never to nothing.
Not model-assertable
Every agent tool resolves the acting human and gates independently. Telling a model somebody's role authorises nothing at all.
Agent controls.
The questions a reviewer actually asks about letting a language model near a production database.
Approval
Always on
No environment variable disables it. The only bypass is an internal flag on two replay paths, which is how an already-approved action executes.
Blocking
5 of 15
Five actions that reach a third party stop the run. The rest queue and the agent continues.
Auto-approval
Two signals
Needs both a policy verdict frozen at enqueue time and a standing rule enabled by a human with approval rights who is not the requester.
Unattended runs
Narrowed
May only do what a standing rule already covers. Anything else becomes an owned task and a notification, never a silent queue row.
Spend cap
Hard ceiling
Refuses at the start of a run, not mid-way. The interface can only tighten under the deployment's ceiling, and no agent tool can write the budget or alert tables.
Guardrails
Configurable
Prompt-injection, moderation and PII processors on the paths where untrusted text reaches an agent: retrieval chunks, chat channel messages and external tool responses. Violations are audited.
Trace redaction
Always on
A sensitive-data filter runs over span output before any trace is stored.
Schedules
No agent tool
No agent can pause, resume or run a schedule, because every alarm in the product sits on one.
Data protection and abuse controls.
Most of these exist because the product fetches URLs and parses feeds that somebody else controls.
Secrets at rest
External connection credentials and webhook URLs are encrypted with AES-256-GCM, versioned by a prefix so an existing deployment can adopt the key without a migration.
Audit trail
Every write records who made it and on whose behalf, agent writes and guardrail violations included. Audit events can be delivered outbound to another system through a retrying webhook queue.
Outbound fetches
One shared fetcher for every URL a user supplies: per-hop revalidation rather than trusting the first check, manual redirect handling, credentials dropped the moment the origin changes, an abort timeout and a body cap. Private address ranges are refused unless explicitly allowed for a LAN target.
Feed parsing
RSS, Atom and JSON are read by a hand-written scanner rather than an XML library, specifically so entity expansion cannot become a denial of service against a scheduler tick.
Realtime stream
Server-sent events carry a topic name and never a record, so the stream itself cannot leak data.
Rate limits
Every agent entry point is limited: dashboard chat, the generate endpoint and both MCP transports. Competitor scans are limited per host so the product cannot be used as an amplifier.
What is actually verified, rather than asserted.
Several of the claims on this page are pinned by tests, so a later edit cannot quietly undo one.
170 test files
Across the library, agent, application and database layers. The unit suite runs fully offline, with no database and no model calls, and lint, typecheck and unit tests run in CI on every change.
End to end
A Playwright suite that creates its own isolated user, seeds deterministic fixtures, then removes its user, rows, sessions and memory threads afterwards. Named coverage includes unauthenticated redirects, cross-resource ownership rejection, recall beyond the model context window, task board drag ordering and the full customer import path.
Pinned invariants
Which tools count as destructive, that no agent tool writes the spend tables, and that the environment variable which sounds like it disables the approval gate changes nothing. Each is a test, not a convention.
Traceable origin
Source and agent identifiers are recorded on spans, so whether a write came from the dashboard, a chat channel, the API or a schedule is always answerable after the fact.
On certification, plainly.
YumaOS does not hold SOC 2, ISO 27001 or IRAP certification, and nobody here will imply otherwise. What exists is the control surface those questionnaires ask about, listed above and demonstrable in a running deployment.
Because the product is single-tenant, data residency, retention and backup policy are decisions you make with Yuma IT for an Australian-hosted deployment, or in your own environment when you run the infrastructure yourself. Those are not defaults you inherit from a global multi-tenant vendor.
