SOC2C

YeshID security & compliance

An overview of YeshID's security posture — compliance, penetration testing, subprocessors, and data handling — verified on SOC2C (Listed).

SOC 2 statusSOC 2 Type II · Listed
FrameworksSOC 2 Type II
Penetration testNot listed
Subprocessors11 listed
HostingGCP
Trust centerView

Security questions about YeshID

Is YeshID secure?
Security isn't a single yes/no, but YeshID is SOC 2 Type II compliant. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does YeshID have a bug bounty or vulnerability disclosure program?
YeshID hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@yeshid.com or via a /security page (YeshID lists a security contact).
Who are YeshID's subprocessors?
YeshID lists 11 subprocessors on its trust center, including Google Cloud Platform, Google Workspace, Better Stack, Stripe, posthog. Buyers use this for fourth-party risk review.
Where does YeshID host or store data?
YeshID hosts on GCP. Data residency details are on its trust center.
Where is YeshID's trust center or security page?
YeshID's trust center is at https://trust.yeshid.com. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.

See YeshID's full SOC 2 profile →