> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ycloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and Privacy

> At YCloud, we are committed to data security and privacy protection.

At YCloud, safeguarding customer privacy and data security is our unwavering commitment. We approach every detail that could affect you with meticulous care, leveraging our professional team and robust mechanisms to fortify an impenetrable defense for your data security and privacy protection.

## Security Strategy Design

YCloud employs a defense-in-depth approach, implementing multi-layered security measures across the organization. Our security strategies are driven not only by compliance and regulatory requirements but also by industry best practices such as OWASP Top 10 and CIS Critical Security Controls and threat intelligence. We are continuously refining our existing security controls.

## **Data Security**

YCloud utilizes various DataStores to store data and ensure its security. Each DataStore configuration adheres to best practices for data security and recovery.

When data within the platform is replicated across multiple service clusters, should a server in one service cluster fail, processing will switch to a backup server in another service cluster, minimizing service interruption impacts.

Our disaster recovery strategy combines data snapshots and daily full backups to ensure multiple copies of data are available for recovery. Snapshots are designed to provide a quick recovery mechanism, with recovery possible within minutes. Full backups are used when snapshots cannot restore the data.

## **Communication Security**

All communications between web clients and YCloud servers are protected using the TLS (1.0, 1.1, 1.2) protocol with strong cipher suites.

All pages on YCloud are securely loaded via HTTPS.

## **System Reliability**

Each service in YCloud's microservices architecture is distributed across multiple servers running in different data centers. These services communicate with each other via APIs to reduce interdependencies. Each update is tested in the corresponding test environment before deployment.

YCloud also leverages a global Content Delivery Network (CDN) to distribute content to the nearest location to users, ensuring fast and consistent access no matter where you are.

## **Infrastructure Security**

We utilize security products such as HIDS and WAF to ensure your data security, protecting your information with top-tier infrastructure security measures.

## Phone number masking

To protect sensitive customer information, YCloud supports phone number masking through **Data desensitization**.

Go to **Settings > Security** and enable **Data desensitization**. After it is enabled, customer phone numbers displayed on the YCloud platform are partially replaced with asterisks. Only limited digits at the beginning and end remain visible, for example: `+1 22****0398`.

This reduces unnecessary exposure of complete customer phone numbers when team members use the platform.

<Info>
  Phone number masking changes how sensitive information is displayed in YCloud. It does not modify the customer's actual phone number.
</Info>

<Frame caption="Use the Data desensitization switch to control phone number masking.">
  <img src="https://mintcdn.com/lchnan/gXEJIQXV2JH2VUQJ/product-assets/english-help-2026-09-22/security-masking-annotated.svg?fit=max&auto=format&n=gXEJIQXV2JH2VUQJ&q=85&s=3e18b97b54502534faf7e04b0c539b07" alt="Data desensitization setting, currently off in the demo account." width="3024" height="1656" data-path="product-assets/english-help-2026-09-22/security-masking-annotated.svg" />
</Frame>

## Audit logs

Audit logs help administrators review security-relevant account activity and investigate who performed an action, when it occurred, and where it originated.

Go to **Settings > Audit logs**. Logs are organized into three categories:

* **Operations:** Actions performed within the YCloud account.
* **Authentication:** Sign-in and other authentication-related activity.
* **CLI:** Activity performed through supported command-line tools.

You can search or filter logs by operator name or email, request ID, and time range. Each record includes information such as:

| Field | Description |
| - | - |
| **Time** | When the event occurred. |
| **Event** | The recorded action or event type. |
| **Operator** | The user who performed the action. |
| **IP address** | The IP address associated with the activity. |
| **Source** | Where the activity originated, such as the YCloud dashboard. |
| **Details** | Additional information about the event. Click **View** to inspect it. |

<Note>
  Audit logs are retained for 180 days. Each query can cover a time range of up to 30 days.
</Note>

For other related content, please refer to:

[Terms of Service](https://www.ycloud.com/terms-service)

[Privacy Policy](https://www.ycloud.com/privacy-policy)

[Shopify Store Privacy Agreement](https://www.ycloud.com/sp-policy)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.