SECURITY ARCHITECTURE & CONTROLS
Security Architecture & Controls
How YAS.SH protects links, accounts, APIs, and infrastructure: defense-in-depth encryption, session hardening, and SSRF containment.

Authentication & Sessions
Bcrypt password hashing (cost 12), hashed opaque session tokens, and optional TOTP 2FA.
Hardened Security Headers
HSTS preloaded for 2 years, strict Content-Security-Policy, and X-Frame-Options: DENY clickjacking guards.
Network & SSRF Hardening
Network tools reject loopback, RFC 1918, and cloud-metadata destinations after hostname and DNS checks.
Scoped API Key Isolation
Scoped API keys with granular permissions, cryptographically signed webhooks, and atomic rate limiting.
Vulnerability Disclosure (Security.txt)
We adhere to RFC 9116 standards at /.well-known/security.txt. We welcome coordinated vulnerability reports from security researchers via hello@yas.sh.