Security50 permissions170 test files

Written for the person your buyer forwards this to.

Isolation between customers is isolation between deployments, which is the strongest form of it. Everything below is a property of the running product, and where a control depends on configuration this page says so rather than glossing it.

Supply Nation CertifiedSupply Nation Certified Supplier (opens in a new tab)
  • Supply Nation Certified

    Delivered by Yuma IT, an Indigenous-led business verified for supplier diversity procurement.

  • Australian hosted & managed

    Yuma IT stands up and supports each deployment onshore. Where the data lives is a design choice, not a region toggle.

  • Single-tenant

    One organisation per deployment. One dedicated database. No shared multi-tenant tenancy and no workspace switch.

  • Human approval on consequence

    Destructive agent actions queue or block. There is no environment variable that switches the gate off.

Security and sovereignty

Where the data actually sits.

One deployment serves one organisation. Application tables carry no organisation or workspace column, which is also why there is no workspace switching to get wrong. Yuma IT hosts and manages deployments in Australia by default; customer-controlled infrastructure remains an option.

Application data

All of it lives in your own database on customer-controlled or Australian-hosted infrastructure. The application and the database are separate components of one dedicated deployment.

Australian hosting

When Yuma IT operates the deployment, application data and agent history sit onshore in Australia under our management. Residency is the commercial model, not a multi-region marketing toggle on a shared tenancy.

Uploaded files

Wherever you point the storage driver: local disk, S3, Cloudflare R2 or Azure Blob. File residency is your decision, not a vendor default.

Chat history

Agent memory and message bodies are stored separately from application tables on purpose, so a routine schema upgrade can never drop conversation history.

Egress

Data leaves the deployment only towards services you configure: your model provider, your email and SMS providers, Xero, Buffer, Slack or Teams, and the feeds you asked it to monitor. Nothing else has an address to send to.

Operator identity

Yuma IT (Supply Nation Certified, Canberra) implements, backs up, and supports the deployment. Publisher credentials and product security controls are stated separately; neither stands in for the other.

Authentication.

Passwords are the floor, not the design.

Sessions

Email and password sign-in. Self-registration is switched off for a deployed-per-client install, because the product is installed for a known organisation rather than joined.

Single sign-on

Microsoft Entra ID, with Entra group to role mapping and a synced user link. Needs an app registration in your tenant.

Two-factor

TOTP with backup codes. Enabling writes an unverified factor and only a successful code activates it, so nobody locks themselves out against a secret they never typed correctly.

Passkeys

WebAuthn with the relying-party ID pinned in code rather than derived. Passkeys are refused, with a stated reason, on an IP-literal or plain-HTTP origin rather than bound to a name that will break.

MFA recovery

Destruction and re-enrolment only. Second factors and backup codes are encrypted at rest, so no operator can read a code back out.

Admin reset

Clearing somebody's second factor revokes their live sessions and is audited under the administrator's name. It sits behind its own permission, not behind user administration, because after a reset the account is reachable with a password alone.

Provisioning

SCIM 2.0 Users and Groups with bearer tokens, discovery, filtering, and separate rate limits for requests and authentication failures.

Machine access

A single API key compared in constant time, or a browser session. Both resolve to a real person's permissions.

Authorisation is fifty reasoned splits, not three tiers.

Approving an agent action is separate from managing agents. Promoting an estimate to a quote is separate from editing estimates. Each split carries the argument for why it exists.

How a permission resolvesPer request

tier baseline + assigned roles + grants - denies

Denies are applied last. Custom roles, per-person grants and per-person denies are database-backed and resolved at request time, not baked into a session.

Repairable

The admin tier holds every action unconditionally and cannot be denied one, so a broken permission row can always be fixed from inside the product.

Fails to the matrix

An unreadable permission table falls back to the static tier matrix. Never to everything, and never to nothing.

Not model-assertable

Every agent tool resolves the acting human and gates independently. Telling a model somebody's role authorises nothing at all.

Agent controls.

The questions a reviewer actually asks about letting a language model near a production database.

Approval

Always on

No environment variable disables it. The only bypass is an internal flag on two replay paths, which is how an already-approved action executes.

Blocking

5 of 15

Five actions that reach a third party stop the run. The rest queue and the agent continues.

Auto-approval

Two signals

Needs both a policy verdict frozen at enqueue time and a standing rule enabled by a human with approval rights who is not the requester.

Unattended runs

Narrowed

May only do what a standing rule already covers. Anything else becomes an owned task and a notification, never a silent queue row.

Spend cap

Hard ceiling

Refuses at the start of a run, not mid-way. The interface can only tighten under the deployment's ceiling, and no agent tool can write the budget or alert tables.

Guardrails

Configurable

Prompt-injection, moderation and PII processors on the paths where untrusted text reaches an agent: retrieval chunks, chat channel messages and external tool responses. Violations are audited.

Trace redaction

Always on

A sensitive-data filter runs over span output before any trace is stored.

Schedules

No agent tool

No agent can pause, resume or run a schedule, because every alarm in the product sits on one.

Data protection and abuse controls.

Most of these exist because the product fetches URLs and parses feeds that somebody else controls.

Secrets at rest

External connection credentials and webhook URLs are encrypted with AES-256-GCM, versioned by a prefix so an existing deployment can adopt the key without a migration.

Audit trail

Every write records who made it and on whose behalf, agent writes and guardrail violations included. Audit events can be delivered outbound to another system through a retrying webhook queue.

Outbound fetches

One shared fetcher for every URL a user supplies: per-hop revalidation rather than trusting the first check, manual redirect handling, credentials dropped the moment the origin changes, an abort timeout and a body cap. Private address ranges are refused unless explicitly allowed for a LAN target.

Feed parsing

RSS, Atom and JSON are read by a hand-written scanner rather than an XML library, specifically so entity expansion cannot become a denial of service against a scheduler tick.

Realtime stream

Server-sent events carry a topic name and never a record, so the stream itself cannot leak data.

Rate limits

Every agent entry point is limited: dashboard chat, the generate endpoint and both MCP transports. Competitor scans are limited per host so the product cannot be used as an amplifier.

What is actually verified, rather than asserted.

Several of the claims on this page are pinned by tests, so a later edit cannot quietly undo one.

170 test files

Across the library, agent, application and database layers. The unit suite runs fully offline, with no database and no model calls, and lint, typecheck and unit tests run in CI on every change.

End to end

A Playwright suite that creates its own isolated user, seeds deterministic fixtures, then removes its user, rows, sessions and memory threads afterwards. Named coverage includes unauthenticated redirects, cross-resource ownership rejection, recall beyond the model context window, task board drag ordering and the full customer import path.

Pinned invariants

Which tools count as destructive, that no agent tool writes the spend tables, and that the environment variable which sounds like it disables the approval gate changes nothing. Each is a test, not a convention.

Traceable origin

Source and agent identifiers are recorded on spans, so whether a write came from the dashboard, a chat channel, the API or a schedule is always answerable after the fact.

On certification, plainly.

YumaOS does not hold SOC 2, ISO 27001 or IRAP certification, and nobody here will imply otherwise. What exists is the control surface those questionnaires ask about, listed above and demonstrable in a running deployment.

Because the product is single-tenant, data residency, retention and backup policy are decisions you make with Yuma IT for an Australian-hosted deployment, or in your own environment when you run the infrastructure yourself. Those are not defaults you inherit from a global multi-tenant vendor.