Trust
Trust at Yembo
Our customers trust Yembo to be a responsible steward of their data. We hold the licenses and certifications the industries and jurisdictions we operate in require, and we publish the evidence rather than describe it.
Security and compliance
Each section carries the current position and the evidence behind it, in the form a security review asks for.
Registrations
Yembo, Inc. is incorporated in Delaware and registered to do business in California. Both filings are public and can be confirmed with the state directly.
Delaware
C Corporation
- Registered
- April 2016
- File number
- 6023452
California
Registered foreign corporation
- Registered
- April 2016
- File number
- 3900952
Compliance
Our security program protects both our organization and your customer data at every level. The certificate or report behind each attestation is linked directly.
ISO/IEC 27001:2022
Certified information security management system, audited by an accredited body.
Official certificate, PDFSOC 2 Type II
Audited operating effectiveness of the security and availability controls.
2025 report, PDFCMMC 2.0 Level 2
Controlled unclassified information handling for federal and defense work.
2026 self-assessment report, PDFGDPR
Processes and procedures covering personal data belonging to subjects in the European Union.
Security
Enterprise-grade data protection, in a form you can inspect without contacting us first.
Security Practices
The technical and organizational controls that protect your data.
Trust Report (opens in a new window)
The live control monitoring dashboard, updated continuously by Vanta.
SSL Certificate Grade (opens in a new window)
Grade the transport security of the application yourself through Qualys SSL Labs.
60-Minute Security Audit (opens in a new window)
A prepared answer to the questions a security review asks first, as a PDF.
Availability
We run the platform to industry-leading availability practices, and the status of every service is public 24 hours a day.
Transparency
How we operate, what we do with data, and which technology partners are involved.
Core Values
The values that govern how we build and how we handle data.
Data Storage Policy
Where data is stored, how long it is retained, and how it is deleted.
Subprocessor List
The third parties that process customer data, and what each is used for.
Code of Conduct
The standards expected of employees, contractors, and partners.
Data Protection Agreement
The terms that apply when we process personal data on your behalf.