Third Party Index

Snapshot 39435

Document
Subprocessor list
URL
https://trust.yellow.ai/?itemUid=e3fae2ca-94a9-416b-b577-5c90e382df57
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
561565 bytes
SHA-256 (raw)
497c0a501bbcb92e023fd7ad0c0baada55365855abd28efd28a92046bedcf97b
SHA-256 (normalized text)
487dcd17c7271ff055c9cfd48759deef0794f86eef226184a200d7b2aa750154

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Yellow AI Trust Center
Start your security review
View & download sensitive information
Ask for information
Overview
Welcome to Yellow.ai's Trust Center. Our commitment to data privacy and security is embedded in every part of our business. Use this Trust Center to learn about our security posture and request access to our security documentation.
Our compliance program is independently audited against multiple international standards. We are certified with ISO/IEC 27001:2022, ISO/IEC 27701:2019, and SOC 2 Type II attested. We comply with applicable data protection laws as both "Processor" & "Controllers". Our audit reports and certificates are accessible upon request after signing an NDA.
To demonstrate our proactive stance on threat detection, we operate a dedicated Vulnerability Disclosure Program (VDP). We actively collaborate with the global security community to identify, report, and rapidly resolve potential vulnerabilities, ensuring our system remains hardened against evolving threats.
Compliance
HIPAA
ISO/IEC 27001:2022
ISO/IEC 27701:2019
SOC 2 Type 2
CCPA
PCI DSS v4.0.1
Yellow.ai Trusted by 1300+ Global Brands including
Logitech
Decathlon
Ferrellgas
Bajaj Auto Ltd
LuLu Group International
Manipal Hospitals
ICICI Lombard GIC
Haldirams
Leadspace
Burger King
DAZN
Lion Air
iFly Airlines
VIPdesk Connect
Lenovo
Cherry Technologies
Documents
REPORTSHIPAA Report
REPORTSWebApp Security AssessmentReport
COMPLIANCEHIPAA
COMPLIANCEISO/IEC 27001:2022
COMPLIANCEISO/IEC 27701:2019
COMPLIANCEPCI DSS v4.0.1
COMPLIANCESOC 2 Type 2
PRODUCT SECURITYAudit Logging
PRODUCT SECURITYRole-Based Access Control
DATA SECURITYAccess Monitoring
DATA SECURITYData Backups
DATA SECURITYEncryption-at-rest
Risk Profile
Impact LevelSevere
Recovery Time Objective4 hours
Recovery Point Objective4 hours
View more
Product Security
Audit Logging
Integrations
Multi-Factor Authentication
View more
Reports
HIPAA Report
Network Diagram
SOC 2 Report
View more
Self-Assessments
VSA Full
Data Security
Access Monitoring
Certificates of Destruction
Data Backups
View more
App Security
Responsible Disclosure
Application Penetration Testing
Bot Detection
View more
AI
AI Overview
AI Training Data and Bias
AI Security
View more
ESG
Anti-Bribery and Corruption
Anti-Competitive Practices
Code of Ethics
View more
Legal
Subprocessors
Customer Audit Rights
Data Processing Agreement
View more
Data Privacy
Data Breach Notifications
Data Privacy Officer
Data Protection Impact Assessment (DPIA)
Access Control
Access Log Management
Bring Your Own Device (BYOD)
Data Access
View more
Infrastructure
Status Monitoring
Cloud Service Providers
Infrastructure Security
View more
Endpoint Security
Disk Encryption
DNS Filtering
Endpoint Detection & Response
View more
Network Security
Distributed Denial of Service Protection (Anti-DDoS)
IDS/IPS
Network Penetration Testing
View more
Corporate Security
Asset Management Practices
Email Protection
HR Security
View more
Policies
Log Management Policy
Acceptable Use Policy
Responsible Disclosure Policy
View more
Security Grades
We are constantly monitoring the security of our website. We will post our grades from public security rating agencies when they become available.
Incident Response
Incident Reporting Process
Risk Management
Risk Assessments
Supply Chain Risk Management
Asset Management
We have strict asset management policies in place to ensure that all assets are accounted for and secure.
BC/DR
Business Continuity Test
Backup & Restoration Test
Disaster Recovery Drill Test
Training
Employee Privacy Training
Role-Based Training
Security Awareness Training
Change Management
We have a change and configuration management process in place to ensure that changes are properly reviewed and approved.
Physical & Environment
Alarms & Surveillance
Emergency Power & Lighting
Fire Protection
View more
Continuous Monitoring
Automated Alert Response
Event & Audit Log Management
Subprocessors
Yellow AI Trust Center Updates
Yellow.ai Attains PCI DSS Compliance as a Service Provider
Compliance
Yellow.ai has officially renewed its PCI DSS Service Provider compliance. This certification confirms that our platform’s infrastructure meets the stringent global standards required for secure financial data processing. Our latest Attestation of Compliance (AOC) & Certificate of Compliance (COC) is now available for download under the "Documents" section of this portal for all verified partners.
Latest SOC 2 Type II Report for Yellow.ai is Now Available!
Compliance
We are pleased to announce that Yellow.ai’s most recent SOC 2 Type II Report, covering the period of December 01, 2024, to November 30, 2025, is now available for review through our SafeBase Trust Center.
This latest audit confirms that our internal controls meet the rigorous Trust Services Criteria for:
Security
Availability
Confidentiality
Accessing the Report: Customers and partners with authorized access can download the full report directly from the "Documents" section of this portal.
If you need help using this Yellow AI Trust Center, please contact us.
Contact support
If you think you may have discovered a vulnerability, please send us a note.
Report issue