Security Strategy Design
YCloud employs a defense-in-depth approach, implementing multi-layered security measures across the organization. Our security strategies are driven not only by compliance and regulatory requirements but also by industry best practices such as OWASP Top 10 and CIS Critical Security Controls and threat intelligence. We are continuously refining our existing security controls.Data Security
YCloud utilizes various DataStores to store data and ensure its security. Each DataStore configuration adheres to best practices for data security and recovery. When data within the platform is replicated across multiple service clusters, should a server in one service cluster fail, processing will switch to a backup server in another service cluster, minimizing service interruption impacts. Our disaster recovery strategy combines data snapshots and daily full backups to ensure multiple copies of data are available for recovery. Snapshots are designed to provide a quick recovery mechanism, with recovery possible within minutes. Full backups are used when snapshots cannot restore the data.Communication Security
All communications between web clients and YCloud servers are protected using the TLS (1.0, 1.1, 1.2) protocol with strong cipher suites. All pages on YCloud are securely loaded via HTTPS.System Reliability
Each service in YCloud’s microservices architecture is distributed across multiple servers running in different data centers. These services communicate with each other via APIs to reduce interdependencies. Each update is tested in the corresponding test environment before deployment. YCloud also leverages a global Content Delivery Network (CDN) to distribute content to the nearest location to users, ensuring fast and consistent access no matter where you are.Infrastructure Security
We utilize security products such as HIDS and WAF to ensure your data security, protecting your information with top-tier infrastructure security measures.Phone number masking
To protect sensitive customer information, YCloud supports phone number masking through Data desensitization. Go to Settings > Security and enable Data desensitization. After it is enabled, customer phone numbers displayed on the YCloud platform are partially replaced with asterisks. Only limited digits at the beginning and end remain visible, for example:+1 22****0398.
This reduces unnecessary exposure of complete customer phone numbers when team members use the platform.
Phone number masking changes how sensitive information is displayed in YCloud. It does not modify the customer’s actual phone number.
Use the Data desensitization switch to control phone number masking.
Audit logs
Audit logs help administrators review security-relevant account activity and investigate who performed an action, when it occurred, and where it originated. Go to Settings > Audit logs. Logs are organized into three categories:- Operations: Actions performed within the YCloud account.
- Authentication: Sign-in and other authentication-related activity.
- CLI: Activity performed through supported command-line tools.
Audit logs are retained for 180 days. Each query can cover a time range of up to 30 days.

