Skip to content
YAS.SH
SECURITY ARCHITECTURE & CONTROLS

Security Architecture & Controls

How YAS.SH protects links, accounts, APIs, and infrastructure: defense-in-depth encryption, session hardening, and SSRF containment.

YAS.SH Security Architecture and Defense In Depth

Authentication & Sessions

Bcrypt password hashing (cost 12), hashed opaque session tokens, and optional TOTP 2FA.

Hardened Security Headers

HSTS preloaded for 2 years, strict Content-Security-Policy, and X-Frame-Options: DENY clickjacking guards.

Network & SSRF Hardening

Network tools reject loopback, RFC 1918, and cloud-metadata destinations after hostname and DNS checks.

Scoped API Key Isolation

Scoped API keys with granular permissions, cryptographically signed webhooks, and atomic rate limiting.

Vulnerability Disclosure (Security.txt)

We adhere to RFC 9116 standards at /.well-known/security.txt. We welcome coordinated vulnerability reports from security researchers via hello@yas.sh.

Ask YAS AI
🍪 Cookies & privacy. Essential cookies keep you signed in and remember language and theme. Google AdSense and reCAPTCHA are Google technologies: AdSense runs only after Accept All; reCAPTCHA loads on sign-in and contact forms. See how Google uses data: https://policies.google.com/technologies/partner-sites cookie policy · privacy policy.
Settings