Skip to main content
Youzu

Security

Last updated: 2026-07-10

Security is a continuous effort. This page summarises the measures we apply today to protect the youzu.ai website and the Youzu platform, and how to report a vulnerability to us.

Encryption in Transit

All public endpoints are served exclusively over HTTPS (TLS), with HTTP Strict Transport Security enabled. Traffic to our origin infrastructure is likewise encrypted, and our edge network provides protection against denial-of-service attacks.

Application Security

The website ships strict security headers, including a Content Security Policy that limits where scripts can be loaded from, along with frame, content-type, and referrer protections. Platform access is authenticated, and organizations control member roles and per-feature permissions; administrative and account actions are recorded in an audit log available to organization administrators.

Infrastructure

Our services run as containerised workloads on Kubernetes, with staging and production strictly separated. Deployments are made through version-controlled, auditable GitOps pipelines rather than manual changes. AI/ML processing runs in EU cloud regions (AWS Frankfurt and Google Cloud Belgium); application servers are operated in data centers in the EU and other locations under appropriate safeguards.

Data Handling

Customer data is logically separated per tenant. Internal access follows the principle of least privilege and is limited to what is needed to operate and support the service. How we process personal data is described in our Privacy Policy.

Responsible Disclosure

If you believe you have found a security vulnerability in any Youzu service, please report it to [email protected]. Include enough detail for us to reproduce the issue. Machine-readable contact details are published at /.well-known/security.txt.

We ask that you:

  • give us reasonable time to investigate and fix the issue before public disclosure;
  • avoid accessing, modifying, or deleting data that is not yours, and stop once a vulnerability is demonstrated;
  • do not degrade the service for others (for example via denial-of-service testing).

We will acknowledge your report, keep you informed of progress, and will not pursue legal action against research conducted in good faith within these guidelines. We do not currently operate a paid bug bounty program.

Get started

Ready to transform how your customers shop?

Start with a representative catalogue, workflow, and measurable acceptance criteria. Book a walkthrough on your own catalogue.

No credit card. We'll reply within one business day.