Trust & security
Controls you can name, not adjectives.
This page describes the controls built into Ysra today. Compliance certifications are listed only when they are current and approved — not before.
- 01
Scope before action
The repository, knowledge sources, capability grants, and permissions for each session or manager are explicit before work begins.
- 02
Isolated workspaces
Hosted repository work, and the verification that goes with it, runs in isolated environments rather than on shared machines.
- 03
Secrets and credentials
Credentials are controlled by the platform and are not exposed to the model or the workspace beyond the boundary a task requires.
- 04
Approval-gated external writes
Where a workflow requires approval, the exact Slack, Jira, or mail payload is shown before it runs. Change it, and it waits again.
- 05
Candidate-bound evidence
Checks, screenshots, and review attach to the exact candidate that was checked. Stale evidence cannot approve different code.
- 06
Budgets and limits
Model work and spend are bounded by a session limit. Ysra stops before the next paid call; extending it needs your authority.
- 07
Checkpoints and recovery
Interruptions preserve recoverable state. Work can be resumed, rewound, or exported instead of lost.
- 08
Auditability
Events, model calls, tool executions, artifacts, usage, and delivery are recorded for product and audit views.
- 09
Honest failure states
An infrastructure or reviewer failure is never labelled as product success — or as a product defect.
- 10
Data-source permissions
Slack and Jira sources are connected and selected by their owner, and each conversation or manager searches only what it was given. Ysra does not mirror every permission in your organisation.
For security reviews
Bring your questionnaire.
We’ll walk your team through data flows, isolation, credential handling, and the audit trail for the workflows you plan to use — and tell you plainly where the boundaries are today.
Give Ysra the outcome. Keep the authority.
Start a software task, ask from company context, or put a repeatable workflow on a schedule.