Skip to main content
At YCloud, safeguarding customer privacy and data security is our unwavering commitment. We approach every detail that could affect you with meticulous care, leveraging our professional team and robust mechanisms to fortify an impenetrable defense for your data security and privacy protection.

Security Strategy Design

YCloud employs a defense-in-depth approach, implementing multi-layered security measures across the organization. Our security strategies are driven not only by compliance and regulatory requirements but also by industry best practices such as OWASP Top 10 and CIS Critical Security Controls and threat intelligence. We are continuously refining our existing security controls.

Data Security

YCloud utilizes various DataStores to store data and ensure its security. Each DataStore configuration adheres to best practices for data security and recovery. When data within the platform is replicated across multiple service clusters, should a server in one service cluster fail, processing will switch to a backup server in another service cluster, minimizing service interruption impacts. Our disaster recovery strategy combines data snapshots and daily full backups to ensure multiple copies of data are available for recovery. Snapshots are designed to provide a quick recovery mechanism, with recovery possible within minutes. Full backups are used when snapshots cannot restore the data.

Communication Security

All communications between web clients and YCloud servers are protected using the TLS (1.0, 1.1, 1.2) protocol with strong cipher suites. All pages on YCloud are securely loaded via HTTPS.

System Reliability

Each service in YCloud’s microservices architecture is distributed across multiple servers running in different data centers. These services communicate with each other via APIs to reduce interdependencies. Each update is tested in the corresponding test environment before deployment. YCloud also leverages a global Content Delivery Network (CDN) to distribute content to the nearest location to users, ensuring fast and consistent access no matter where you are.

Infrastructure Security

We utilize security products such as HIDS and WAF to ensure your data security, protecting your information with top-tier infrastructure security measures.

Phone number masking

To protect sensitive customer information, YCloud supports phone number masking through Data desensitization. Go to Settings > Security and enable Data desensitization. After it is enabled, customer phone numbers displayed on the YCloud platform are partially replaced with asterisks. Only limited digits at the beginning and end remain visible, for example: +1 22****0398. This reduces unnecessary exposure of complete customer phone numbers when team members use the platform.
Phone number masking changes how sensitive information is displayed in YCloud. It does not modify the customer’s actual phone number.
Data desensitization setting, currently off in the demo account.

Use the Data desensitization switch to control phone number masking.

Audit logs

Audit logs help administrators review security-relevant account activity and investigate who performed an action, when it occurred, and where it originated. Go to Settings > Audit logs. Logs are organized into three categories:
  • Operations: Actions performed within the YCloud account.
  • Authentication: Sign-in and other authentication-related activity.
  • CLI: Activity performed through supported command-line tools.
You can search or filter logs by operator name or email, request ID, and time range. Each record includes information such as:
Audit logs are retained for 180 days. Each query can cover a time range of up to 30 days.
For other related content, please refer to: Terms of Service Privacy Policy Shopify Store Privacy Agreement