AI providers that keep nothing
Every request to an AI model goes through OpenRouter and asks it to use only providers that keep no copy of the request and don't use it for training (OpenRouter's zero data retention setting, with data collection denied). That is the providers' commitment under OpenRouter's policies; we can't inspect their systems ourselves. Models that have no such provider are left out.
We don't use your documents or results to train AI models. That is off for every workspace and would only be switched on with your agreement.
Secrets and passwords
- Encrypted at rest: the AI provider key we create for each workspace, the sign-in tokens of apps you connect, and the addresses and passwords of databases you connect are stored encrypted (Fernet, with a key held by the server).
- Sign-in codes are stored only as a keyed hash, last 10 minutes, allow 5 tries and work once.
- Passkeys: we keep only the public key. The private key stays on your device or password manager.
- Card details go to Stripe and never reach us.
Your databases and links
- Databases are read, never written. Where the database supports it, the connection itself is set to read-only. On top of that, each query must be a single read-only SELECT, has a time limit and returns at most 5,000 rows. We still recommend connecting with a read-only database user.
- No reaching into private networks. Connections to private or internal network addresses are refused, so a connection string can't be used to probe our network.
- Links you add are fetched only from public addresses, on the normal web ports, up to 15 MB, with a 20-second limit.
- Read-only connectors for apps such as Google Drive, SharePoint and Xero are coming soon; they are not available yet.
Signing in
You sign in with a one-time code sent to your email address, or with a passkey. Codes and passkeys mean there is no Yellowjacket password to steal or reuse. Once you're signed in, your browser holds a random session token in a cookie that page scripts can't read (HttpOnly), sent only over HTTPS; we store only a hash of it. A session lasts 90 days and renews while you keep using it.
Sending a sign-in email and opening a new workspace are protected by Cloudflare Turnstile, a bot check that is invisible for almost everyone.
Apps and code the AI writes
- Apps are previewed in a sealed, sandboxed origin: they can't read your Yellowjacket session, can't send requests to other sites and their forms can't post anywhere. Their automatic checks run in a headless browser with the network blocked.
- Software builds: the tests the AI writes run in a separate process with memory and process limits and, where the server allows it, with no network, as an unprivileged user that can't see the server's other processes or its data folders. Each build records which of these protections it ran under.
This is containment, not a separate machine: the code runs on the same server (and the same operating system kernel) as the rest of the service. Review generated code before you run it yourself.
Where it runs and backups
Yellowjacket runs on Cloudflare, and every connection is over HTTPS. The service's data (accounts, work orders and results, saved plans, encrypted connection details) is backed up to Cloudflare R2 storage every few minutes when something has changed, with a dated copy kept each day. Original files you upload are not included in backups, except while a job is waiting for credit to start.
What we don't claim
We don't hold any security certification or audit (such as SOC 2 or ISO 27001), and Yellowjacket is not set up for health records under rules such as HIPAA. Everything on this page describes how the code works today, and we say where it falls short.
Found a problem? Email hello@aiyellowjacket.com. How we handle personal information is on the privacy page.
Questions people ask
Do the AI providers keep or train on my documents?
Every AI request asks OpenRouter for providers with zero data retention that don't use data for training, and names, contact details and ID numbers are swapped for placeholders first (unless you switch that off). Photos and scanned pages are sent as pictures.
Does Yellowjacket train AI models on my work?
No. Training on your work is off for every workspace and would only be switched on with your agreement.
Is Yellowjacket SOC 2 or ISO 27001 certified?
No. We don't hold any security certification or audit. This page describes what the service does today.
Can Yellowjacket change my database?
No. Connections are read-only where the database allows it, every query must be a single read-only SELECT, and we recommend a read-only database user as well.
How do I report a security problem?
Email hello@aiyellowjacket.com.