TRUST CENTER

Trust starts with verifiable status

We separate implemented controls, deployment-specific behavior, plans, and claims that are not yet verified.

PUBLIC REGISTER

Current control status

Status applies only to the stated scope. Missing evidence is not replaced by a marketing promise.

DEPLOYMENT BOUNDARIES

SaaS, Private, and Enterprise are not one promise

Data, provider, retention, and operational behavior is evidenced separately for each deployment.

Beta

Managed SaaS

A Wicsora-managed deployment with no published HA or SLA guarantee.

Current single-site runtime is not HA/SLA evidence.
Planned

RU private cloud

A planned private-cloud deployment in Russia.

No customer infrastructure acceptance.
Planned

Customer-dedicated

A customer-dedicated deployment after technical assessment.

No dedicated production build evidence.
Beta

On-Prem

Customer-environment packaging with outbound access denied by default.

Signed artifacts and a customer restore drill are still required.
Unavailable

disconnected

A disconnected deployment is not available as an approved release.

Current release artifacts are not an approved signed offline bundle.
ControlStatusScopeEvidence / notes
Public-site TLSImplementedyasnora.ruHTTPS and redirect behavior are checked during production deployment.Verified: 2026-08-22
Encryption at restDeployment-dependentDefined by the selected deploymentNot claimed universally without evidence for the specific infrastructure.Owner: security@yasnora.ai
Role-based accessNot verifiedApplication and enterprise deploymentsCurrent implementation evidence is not yet connected to the public site.Owner: security@yasnora.ai
Workspace isolationDeployment-dependentApplication; deployment-dependentServer-side tenant and workspace scope is covered by automated tests; independent production testing is pending.Owner: security@yasnora.ai
Action auditNot verifiedPlan- and deployment-dependentNot presented as available until confirmed by the application registry.Owner: security@yasnora.ai
BackupsDeployment-dependentSpecific production deploymentRecovery parameters and targets are defined per deployment or contract.Owner: security@yasnora.ai
Data location and residencyNot verifiedLocal / Hybrid / permitted external modesUniversal Russian residency is not claimed: stores, logs, backups, providers, and the active deployment policy require evidence.Owner: privacy@yasnora.ai
External AI routingDeployment-dependentOnly under permitted configurationTests prevent prohibited external fallback; the active production policy is not verified.Owner: privacy@yasnora.ai
Retention and deletionNot verifiedDepends on data type and deploymentThe retention matrix and deletion chain remain under review.Owner: privacy@yasnora.ai
SSO / SCIMPlannedEnterprise deploymentsNot represented as an implemented capability.Owner: support@yasnora.ai
Server-side routing policyDeployment-dependentYasnora Auto and AI gatewayCode applies policy, residency, and capability before economics; production activation is not verified.Owner: security@yasnora.ai
Routing telemetry minimizationDeployment-dependentRouting decisions and outcomesThe artifact records technical metadata without prompt text; the full logging audit is pending.Owner: security@yasnora.ai