Security Overview

Effective July 15, 2026 · Last updated July 10, 2026

YupUp is building a risk-based security program appropriate for an early-stage SaaS company. This overview describes intended baseline practices. It is not a certification, audit report, warranty, or guarantee.

Baseline commitments

  • Governance — Named security owner, risk register, written policies, periodic reviews and workforce accountability.
  • Access — Least privilege, unique accounts, multi-factor authentication for privileged access, periodic access review and prompt offboarding.
  • Data protection — Encryption in transit; encryption at rest for production data where supported; secrets management; restricted production access; data classification and minimization.
  • Application security — Peer review, dependency scanning, secret scanning, vulnerability remediation, controlled releases and environment separation.
  • Infrastructure — Managed cloud services, secure configuration, logging, backup, patching and monitoring appropriate to risk.
  • Incident response — Documented triage, containment, investigation, notification decision, recovery and lessons-learned process.
  • Vendors — Risk-based vendor review, data-protection terms and subprocessor inventory.
  • Business continuity — Backups and restoration testing; documented recovery priorities and contacts.
  • Privacy — Data inventory, retention schedule, rights process, privacy-by-design review and limits on production data use.
  • Messaging — Consent evidence, suppression, keyword handling, quiet-hour controls, campaign review and abuse response.

Shared responsibility

Merchants must secure their accounts, configure roles, limit integrations, maintain lawful data and consent, train users, and notify YupUp of suspected compromise. YupUp may provide security features, but a Merchant remains responsible for its devices, personnel, content, business processes, and third-party systems.

Reporting vulnerabilities

Report suspected vulnerabilities to security@yupup.ai with steps to reproduce and avoid accessing unnecessary data, disrupting service, social engineering, extortion, or public disclosure before a reasonable remediation period. YupUp will acknowledge and coordinate in good faith. This is not a bug bounty promise.