YeshID Security Program
YeshID operates a comprehensive information security program that includes administrative, physical, and technical safeguards to protect its infrastructure, data, services, and customers.
Foundation
YeshID's security program is designed to meet and exceed the SOC 2 Trust Services Criteria, incorporating annually reviewed security policies, clearly defined roles and responsibilities for its experienced professionals, and formal procedures developed with a focus on security, availability, confidentiality, and risk management to ensure the protection and integrity of customer data.
Security policies
YeshID institutes information security policies that are published internally and reviewed annually. The policies contain principles and point to standards that cover controls and procedures designed to protect YeshID and YeshID’s customers.
Experienced professionals
YeshID designates roles and responsibilities for the security of its services. YeshID assigns our Chief Technology Officer oversee its security program.
Risk-based approach
YeshID maintains formal procedures for the identification, assessment, and treatment of information security and availability risks, threats, and vulnerabilities. These procedures ensure that unauthorized access, data breaches, and other security risks are properly managed and mitigated in compliance with best-practice security criteria. Key components of this approach include an annual risk assessment, risk analysis and treatment plan, and a risk register to address and document security-related risks.
- Annual risk assessment: YeshID conducts an annual risk assessment to measure the state of security risk across the company. The results of this assessment are shared with the senior leadership team to ensure appropriate visibility and treatment.
- Risk analysis and treatment plan: Security risks are evaluated and addressed with appropriate controls and mitigation strategies to manage them to acceptable levels.
- Risk register: YeshID maintains a register of identified security risks, which are assessed and remediated by assigned personnel, following standard risk management procedures.
Defense-in-depth
YeshID understands that to adequately protect its services, customers, and customer data, multiple safeguards must be applied to all layers of YeshID’s business and technology practices. YeshID’s process, technology, and physical security controls are designed specifically to provide a defense-in-depth approach and can be categorized as follows:
Identity and access management
YeshID manages access to its production systems using the following:
- Authentication: Employees are required to use unique user accounts and multi-factor authentication for remote access to production systems.
- Authorization: Employee access to production systems is restricted based on appropriate roles.
- Audit: Logs of access attempts (both success and failure) to production systems are kept and monitored.
- Access grants and revocations: Employee access to production systems is granted based on the principle of least privilege and manager approval. That access is reviewed at least quarterly and is removed when no longer needed or upon employee separation. Access roles are enforced by YeshID systems and devices.
Data security
YeshID manages data security using the following:
- Customer credentials management: YeshID secures customer-provided secrets, such as private keys and API tokens, throughout their lifecycle. Secrets are encrypted at rest and in transit using GCP’s encryption. Private keys are stored in encrypted and decrypted only when needed, with access restricted to authorized personnel.
- Authorized access to customer data: YeshID may directly access or modify customer accounts or configurations as necessary to provide the services, prevent or address service or technical issues, as required by law, or as customers expressly permit. For the same reasons, YeshID may also access or modify equipment, systems, or services that manage customer data.
- Privacy and protection-by-design approach: YeshID maintains a "privacy and protection-by-design" approach.
Application security
YeshID manages application security using the following:
- Secure development practices: Code is peer-reviewed and run through automated testing before deployment to production systems. After review and testing, code is initially deployed to a limited number of locations for further monitoring. If no problems are encountered, code is gradually deployed across the YeshID network.
- Application security analysis: YeshID engineers conduct periodic analysis and regular penetration testing of YeshID-written code.
- Automated code analysis: YeshID deploys technology to automatically identify and report on identified vulnerable dependencies.
System and network security
YeshID manages system and network security using the following:
- Asset management: YeshID maintains an inventory of its hardware and services used.
- Configuration standards: YeshID maintains secure configuration standards, including restricted ports, protocols, and services, and removal of insecure default settings.
- Patch management: YeshID patches its production systems on a regular basis and applies out-of-band patches for newly-identified risks.
- Endpoint management: YeshID manages its production systems by verifying appropriate security settings are in place.
- Audit and monitoring: YeshID logs relevant security-related events. YeshID investigates events triggered by anomalous activity or suspicious behavior.
- Documentation: YeshID maintains accurate network diagrams and internal documentation of its systems and services.
- Access Control List (ACL) review: On at least a semi-annual basis, YeshID conducts a production system ACL review of its firewall rulesets.
Human security
YeshID manages human security using the following:
- Confidentiality agreements: To safeguard sensitive information that employees may view, process, or transmit as part of their job functions, all employees enter into confidentiality agreements with YeshID.
- Awareness training: All employees receive security training upon hire and annually thereafter designed to help protect YeshID and its customers. Mandatory annual training includes security awareness that covers application of best security practices in day-to-day work and privacy to ensure each employee understands how to identify sensitive information and comply with regulations.
Continuous monitoring and improvement
To ensure that the controls described above are consistently applied and effective in their intended use, YeshID continuously monitors and improves its security measures. YeshID institutes strict processes and testing procedures as follows.
Change management process
YeshID follows a defined set of procedures to develop and deploy technology changes. These changes include updates to software, configurations, and devices that support YeshID’s services.
- Testing: YeshID tests changes at various stages of development and confirms the changes operate as expected in a non-production environment before completing a deployment into its services.
- Change approval and notification: YeshID prepares, approves, and communicates change notices to maintain awareness among employees who manage the YeshID network and systems. YeshID maintains rollback procedures to address deployment issues if they arise.
- Post-implementation review: YeshID confirms the success of changes after deployment.
- Change monitoring: YeshID uses multiple monitoring and alert mechanisms to enhance the visibility of technical changes and help ensure adherence to change management processes.
Vulnerability management
YeshID monitors for vulnerabilities in its production systems using the following measures:
- Vulnerability scanning: On a regular basis, YeshID automatically analyzes its production systems for vulnerabilities.
- Vulnerability mitigation: YeshID assesses the risk of identified or reported vulnerabilities, and mitigates vulnerabilities in a timely manner. Mitigations for vulnerabilities deemed highest severity are implemented within 1 week of validation.
- Distribution lists and vendor notification: YeshID monitors publicly disclosed and vendor confidential distribution lists and notifications from software vendors for vulnerabilities.
Penetration testing
On an annual basis, YeshID engages a third-party to conduct a penetration test of YeshID production systems. Identified issues are prioritized and handled in order based upon the severity of the evaluated risk they pose.
Compliance and audits
YeshID maintains recurring audits and assessments that confirm its security program meets various industry standards and regulatory requirements.
YeshID vendor management
YeshID uses third-party vendors and service providers to support its services. YeshID evaluates its vendors for security controls and risk to YeshID and its services prior to using vendor services, and regularly thereafter based on vendor risk.
When something goes wrong
YeshID aims to provide a consistently reliable and secure platform. With this in mind, YeshID is always monitoring for threats and systems disruptions so incidents are detected, responded to, and recovered from in a timely manner.
Incident management plan
YeshID maintains a formal incident response plan to address security-related incidents. The plan contains established roles and responsibilities, communication protocols, and response procedures. YeshID reviews and updates the plan periodically to adapt it to evolving threats and risks to its services. Representatives from key departments are assigned to address security-related incidents. These personnel coordinate the full lifecycle of incidents, from detection, through response, and recovery. Included within these processes is communication with external contacts as needed.
Incident notification
YeshID notifies affected customers within forty-eight (48) hours of validating any unauthorized disclosure of customer data. Following any security-related incident, YeshID investigates and takes corrective action in a timely manner according to the incident management plan and provides affected customers with periodic updates.
Business continuity
YeshID maintains a formal business continuity plan to ensure the availability of services during disruptive events. The plan outlines key roles and responsibilities, communication strategies, and recovery procedures to minimize the impact of incidents on business operations. YeshID reviews and updates the plan regularly to address new risks and maintain alignment with evolving operational needs. Personnel from critical departments are responsible for coordinating the full continuity process, from initial assessment through recovery and restoration of services.