Yirla Security & Compliance Controls (SOC 2-Aligned)
Yirla is SOC 2–aligned today, with documented controls for security, access, logging, and data protection. A formal SOC 2 Type I audit is planned as we scale enterprise adoption.

1️⃣ Access Control
RBAC enforced across app and infrastructure
MFA for all privileged accounts
No standing “God mode” access
2️⃣ Audit Logging
All access and admin actions logged
Logs immutable and encrypted
Long-term retention defined
3️⃣ Data Protection
Encryption at rest (AES-256)
Encryption in transit (TLS 1.2+)
No PII ingestion
4️⃣ Change Management
Code changes via PRs
Production deploys logged
Rollback procedures defined
5️⃣ Incident Response
Incident classification
Escalation path
Customer notification process