Why Ycrest

Solutions

Sales

Briefs, objections and forecast

Marketing

Spend that follows revenue

Customer Success

Churn caught early, expansion found

Product

Roadmap ranked by revenue

Procurement

Remembers every negotiation

Book a demo

SECURITY

Your revenue data is sensitive. We treat it that way

This page explains, in plain language, how Ycrest protects the information you trust us with — and the contractual commitments behind it. We regularly review and update our security program; changes enhance and do not materially diminish it.

SOC 2 Type II

In progress — observation period begins July 2026

LAST UPDATED: JULY 15, 2026

privacy@ycrest.ai

  1. Audits & certifications

Ycrest is currently pursuing SOC 2 Type II certification, with the observation period beginning in July 2026. We do not hold other certifications at this time and will update this page as our audit progresses.

In the meantime, the controls described on this page reflect our operating security program. We perform penetration testing of our security infrastructure, and summaries can be made available to customers subject to standard confidentiality obligations. To request our security documentation for your vendor review, email security@ycrest.ai.

  1. Where your data lives

Customer Data is hosted in production cloud environments in the United States and/or the European Union, depending on your service configuration and selection:

UNITED STATES

US regions

AWS us-east-1 · GCP us-central-1

EUROPEAN UNION

EU regions

AWS eu-central-1 · GCP europe-west-3

  1. Encryption

In transit

All data moving between your browser, your integrations, and our servers is encrypted using TLS 1.2 or higher. We enforce HTTPS on all endpoints and redirect plain HTTP requests.

At rest

Customer Data is encrypted at rest using AES 256-bit (or higher) encryption.

Key management

Our encryption key management conforms to NIST 800-53 and involves regular key rotation. Cloud-based hardware security modules (HSMs) safeguard top-level encryption keys.

  1. Data isolation & AI

Each customer's data is logically isolated — we do not commingle your data with other customers'.

Your revenue signal data is never used to train shared models and is never surfaced to other customers in any form.

  1. Infrastructure & network security

Ycrest runs on enterprise-grade cloud infrastructure, designed as a distributed system that spreads processing across multiple physical servers and multiple fault-independent availability zones — so no single hardware or availability-zone failure compromises the availability of the Services or Customer Data.

  • Separation of environments: production is logically separated from development, and both logically and physically separated from our corporate networks.
  • Firewalls: industry-standard firewalls, security groups, and network access controls deny all ingress/egress traffic other than what the business requires.
  • Hardening: the production environment is hardened using industry-standard practices — default passwords changed, unnecessary software and services removed or disabled, and regular patching.
  • Change control: infrastructure changes go through peer review before deployment.
  1. Access controls

Internal access to Customer Data is restricted on a strict need-to-know basis: Ycrest personnel will not access Customer Data except as reasonably necessary to provide the Services under the Agreement, or to comply with applicable law or a binding order of a governmental body.

  • All personnel access to the Ycrest cloud environment uses a unique user ID, follows the principle of least privilege, and requires both VPN and multi-factor authentication.
  • A formalized access management process governs request, review, approval, and provisioning.
  • Access privileges are reviewed on a defined cadence, with mechanisms to identify changes in roles and permissions. Access for separated employees is terminated via an automated deprovisioning checklist.
  • Endpoint controls: access requires Ycrest-issued laptops with disk encryption and endpoint detection and response (EDR) tooling that monitors and alerts on suspicious activity and malicious code.
  1. Monitoring & logging

User logging. Ycrest captures logs of certain activities within customer accounts and makes those logs available via API for your own analysis.

Infrastructure logging. Monitoring tools covering network, cloud environments, and identity solutions log activity in the production environment. Logs are monitored, analyzed for anomalies, and retained for at least one year.

  1. Vulnerability management
  • Penetration testing: independent third parties test the Services at least annually.
  • Vulnerability scanning: the production environment is scanned at least daily using up-to-date vulnerability databases, alongside regular dependency scanning of our codebase.
  • Patching: security patches are applied promptly; critical vulnerabilities in production dependencies are addressed within 24 hours of disclosure.
  • Workload protection: antivirus, anti-malware, and security detection tools monitor the production environment and alert on suspicious activity or potentially malicious code.
  • Bug bounty: ongoing security testing by independent researchers through our responsible disclosure and bug bounty program (see below).
  1. Incident detection & response

We maintain an incident response plan with defined roles and escalation paths.

If Ycrest becomes aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data (a "Security Incident"), we will notify you without undue delay, and no later than 72 hours after discovery — consistent with applicable regulations, including GDPR.

Investigation. We promptly take commercially reasonable steps to contain, investigate, and mitigate any Security Incident. Logs relating to a Security Incident are preserved for at least one year.

Communication and cooperation. Our notification will provide timely information to the extent known — including the nature and consequences of the incident, mitigation and containment measures taken, investigation status, and the categories and approximate number of data subjects and records concerned — along with a Ycrest representative for further information. Communications regarding a Security Incident are not an acknowledgement of fault or liability.

  1. Business continuity & disaster recovery

The Services back up Customer Data at least daily. Ycrest maintains an industry-standard business continuity and disaster recovery plan (the "BCP"), designed to restore the Services in the event of a service failure. The BCP is tested and reviewed annually.

  1. People & vendors
  • Criminal background screening, employment and identity verification as part of hiring, performed in accordance with applicable laws.
  • All employees with access to Customer Data complete security awareness training covering the protection, security, and confidentiality of Customer Data.
  • Personnel sign confidentiality agreements and an information security policy.
  • A vendor risk management program ensures each vendor that processes Customer Data maintains security measures consistent with our commitments.
  1. Third-party integrations

When you connect a data source (CRM, call recording, email, and so on), Ycrest requests only the minimum OAuth scopes necessary. Credentials are stored encrypted and never logged in plaintext. You can revoke any connection at any time from your account settings.

  1. Customer audit rights

Customers assess Ycrest's compliance primarily through our security documentation (and, once issued, our SOC 2 Type II report). Where that isn't sufficient, and no more than once per year (unless required by applicable law), customers may audit Ycrest's compliance with its security obligations following at least 45 days' written notice.

Audits may involve customer third-party consultants not reasonably objected to by Ycrest, subject to appropriate confidentiality obligations. Ycrest provides reasonable assistance, cooperation, and access; audits must not disrupt Ycrest's business or access other customers' information. Except as required by law, scope, methodology, timing, and conditions are mutually agreed in advance.

  1. Responsible disclosure

If you discover a security vulnerability, please report it to security@ycrest.ai with a description of the issue, steps to reproduce, and the potential impact. We'll acknowledge your report within 48 hours and work with you toward a resolution.

We ask that you not publicly disclose the issue until we've had a reasonable opportunity to address it.

We do not take legal action against researchers who act in good faith.

  1. Questions

For security-related questions, or to request our security documentation for your vendor review process:

Ycrest, Inc. — Security Teamsecurity@ycrest.ai

Your team learns from every interaction. We make sure it never forgets.

EXPLORE

Why Ycrest

© 2026 Ycrest. All rights reserved.

Solutions

Book a demo

SECURITY

Your revenue data is sensitive. We treat it that way

This page explains, in plain language, how Ycrest protects the information you trust us with — and the contractual commitments behind it. We regularly review and update our security program; changes enhance and do not materially diminish it.

SOC 2 Type II

In progress — observation period begins July 2026

LAST UPDATED: JULY 2026

security@ycrest.ai

  1. Audits & certifications

Ycrest is currently pursuing SOC 2 Type II certification, with the observation period beginning in July 2026. We do not hold other certifications at this time and will update this page as our audit progresses.

In the meantime, the controls described on this page reflect our operating security program. We perform penetration testing of our security infrastructure, and summaries can be made available to customers subject to standard confidentiality obligations. To request our security documentation for your vendor review, email security@ycrest.ai.

  1. Where your data lives

Customer Data is hosted in production cloud environments in the United States and/or the European Union, depending on your service configuration and selection:

UNITED STATES

US regions

AWS us-east-1 · GCP us-central-1

EUROPEAN UNION

EU regions

AWS eu-central-1 · GCP europe-west-3

  1. Encryption

In transit

All data moving between your browser, your integrations, and our servers is encrypted using TLS 1.2 or higher. We enforce HTTPS on all endpoints and redirect plain HTTP requests.

At rest

Customer Data is encrypted at rest using AES 256-bit (or higher) encryption.

Key management

Our encryption key management conforms to NIST 800-53 and involves regular key rotation. Cloud-based hardware security modules (HSMs) safeguard top-level encryption keys.

  1. Data isolation & AI

Each customer's data is logically isolated — we do not commingle your data with other customers'.

Your revenue signal data is never used to train shared models and is never surfaced to other customers in any form.

  1. Infrastructure & network security

Ycrest runs on enterprise-grade cloud infrastructure, designed as a distributed system that spreads processing across multiple physical servers and multiple fault-independent availability zones — so no single hardware or availability-zone failure compromises the availability of the Services or Customer Data.

  • Separation of environments: production is logically separated from development, and both logically and physically separated from our corporate networks.
  • Firewalls: industry-standard firewalls, security groups, and network access controls deny all ingress/egress traffic other than what the business requires.
  • Hardening: the production environment is hardened using industry-standard practices — default passwords changed, unnecessary software and services removed or disabled, and regular patching.
  • Change control: infrastructure changes go through peer review before deployment.
  1. Access controls

Internal access to Customer Data is restricted on a strict need-to-know basis: Ycrest personnel will not access Customer Data except as reasonably necessary to provide the Services under the Agreement, or to comply with applicable law or a binding order of a governmental body.

  • All personnel access to the Ycrest cloud environment uses a unique user ID, follows the principle of least privilege, and requires both VPN and multi-factor authentication.
  • A formalized access management process governs request, review, approval, and provisioning.
  • Access privileges are reviewed on a defined cadence, with mechanisms to identify changes in roles and permissions. Access for separated employees is terminated via an automated deprovisioning checklist.
  • Endpoint controls: access requires Ycrest-issued laptops with disk encryption and endpoint detection and response (EDR) tooling that monitors and alerts on suspicious activity and malicious code.
  1. Monitoring & logging

User logging. Ycrest captures logs of certain activities within customer accounts and makes those logs available via API for your own analysis.

Infrastructure logging. Monitoring tools covering network, cloud environments, and identity solutions log activity in the production environment. Logs are monitored, analyzed for anomalies, and retained for at least one year.

  1. Vulnerability management
  • Penetration testing: independent third parties test the Services at least annually.
  • Vulnerability scanning: the production environment is scanned at least daily using up-to-date vulnerability databases, alongside regular dependency scanning of our codebase.
  • Patching: security patches are applied promptly; critical vulnerabilities in production dependencies are addressed within 24 hours of disclosure.
  • Workload protection: antivirus, anti-malware, and security detection tools monitor the production environment and alert on suspicious activity or potentially malicious code.
  • Bug bounty: ongoing security testing by independent researchers through our responsible disclosure and bug bounty program (see below).
  1. Incident detection & response

We maintain an incident response plan with defined roles and escalation paths.

If Ycrest becomes aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data (a "Security Incident"), we will notify you without undue delay, and no later than 72 hours after discovery — consistent with applicable regulations, including GDPR.

Investigation. We promptly take commercially reasonable steps to contain, investigate, and mitigate any Security Incident. Logs relating to a Security Incident are preserved for at least one year.

Communication and cooperation. Our notification will provide timely information to the extent known — including the nature and consequences of the incident, mitigation and containment measures taken, investigation status, and the categories and approximate number of data subjects and records concerned — along with a Ycrest representative for further information. Communications regarding a Security Incident are not an acknowledgement of fault or liability.

  1. Business continuity & disaster recovery

The Services back up Customer Data at least daily. Ycrest maintains an industry-standard business continuity and disaster recovery plan (the "BCP"), designed to restore the Services in the event of a service failure. The BCP is tested and reviewed annually.

  1. People & vendors
  • Criminal background screening, employment and identity verification as part of hiring, performed in accordance with applicable laws.
  • All employees with access to Customer Data complete security awareness training covering the protection, security, and confidentiality of Customer Data.
  • Personnel sign confidentiality agreements and an information security policy.
  • A vendor risk management program ensures each vendor that processes Customer Data maintains security measures consistent with our commitments.
  1. Third-party integrations

When you connect a data source (CRM, call recording, email, and so on), Ycrest requests only the minimum OAuth scopes necessary. Credentials are stored encrypted and never logged in plaintext. You can revoke any connection at any time from your account settings.

  1. Customer audit rights

Customers assess Ycrest's compliance primarily through our security documentation (and, once issued, our SOC 2 Type II report). Where that isn't sufficient, and no more than once per year (unless required by applicable law), customers may audit Ycrest's compliance with its security obligations following at least 45 days' written notice.

Audits may involve customer third-party consultants not reasonably objected to by Ycrest, subject to appropriate confidentiality obligations. Ycrest provides reasonable assistance, cooperation, and access; audits must not disrupt Ycrest's business or access other customers' information. Except as required by law, scope, methodology, timing, and conditions are mutually agreed in advance.

  1. Responsible disclosure

If you discover a security vulnerability, please report it to security@ycrest.ai with a description of the issue, steps to reproduce, and the potential impact. We'll acknowledge your report within 48 hours and work with you toward a resolution.

We ask that you not publicly disclose the issue until we've had a reasonable opportunity to address it.

We do not take legal action against researchers who act in good faith.

  1. Questions

For security-related questions, or to request our security documentation for your vendor review process:

Ycrest, Inc. — Security Teamsecurity@ycrest.ai

Your team learns from every interaction. We make sure it never forgets.

EXPLORE

Why Ycrest

© 2026 Ycrest. All rights reserved.

Solutions

Book a demo

SECURITY

Your revenue data is sensitive. We treat it that way

This page explains, in plain language, how Ycrest protects the information you trust us with — and the contractual commitments behind it. We regularly review and update our security program; changes enhance and do not materially diminish it.

SOC 2 Type II

In progress — observation period begins July 2026

LAST UPDATED: JULY 2026

security@ycrest.ai

  1. Audits & certifications

Ycrest is currently pursuing SOC 2 Type II certification, with the observation period beginning in July 2026. We do not hold other certifications at this time and will update this page as our audit progresses.

In the meantime, the controls described on this page reflect our operating security program. We perform penetration testing of our security infrastructure, and summaries can be made available to customers subject to standard confidentiality obligations. To request our security documentation for your vendor review, email security@ycrest.ai.

  1. Where your data lives

Customer Data is hosted in production cloud environments in the United States and/or the European Union, depending on your service configuration and selection:

UNITED STATES

US regions

AWS us-east-1 · GCP us-central-1

EUROPEAN UNION

EU regions

AWS eu-central-1 · GCP europe-west-3

  1. Encryption

In transit

All data moving between your browser, your integrations, and our servers is encrypted using TLS 1.2 or higher. We enforce HTTPS on all endpoints and redirect plain HTTP requests.

At rest

Customer Data is encrypted at rest using AES 256-bit (or higher) encryption.

Key management

Our encryption key management conforms to NIST 800-53 and involves regular key rotation. Cloud-based hardware security modules (HSMs) safeguard top-level encryption keys.

  1. Data isolation & AI

Each customer's data is logically isolated — we do not commingle your data with other customers'.

Your revenue signal data is never used to train shared models and is never surfaced to other customers in any form.

  1. Infrastructure & network security

Ycrest runs on enterprise-grade cloud infrastructure, designed as a distributed system that spreads processing across multiple physical servers and multiple fault-independent availability zones — so no single hardware or availability-zone failure compromises the availability of the Services or Customer Data.

  • Separation of environments: production is logically separated from development, and both logically and physically separated from our corporate networks.
  • Firewalls: industry-standard firewalls, security groups, and network access controls deny all ingress/egress traffic other than what the business requires.
  • Hardening: the production environment is hardened using industry-standard practices — default passwords changed, unnecessary software and services removed or disabled, and regular patching.
  • Change control: infrastructure changes go through peer review before deployment.
  1. Access controls

Internal access to Customer Data is restricted on a strict need-to-know basis: Ycrest personnel will not access Customer Data except as reasonably necessary to provide the Services under the Agreement, or to comply with applicable law or a binding order of a governmental body.

  • All personnel access to the Ycrest cloud environment uses a unique user ID, follows the principle of least privilege, and requires both VPN and multi-factor authentication.
  • A formalized access management process governs request, review, approval, and provisioning.
  • Access privileges are reviewed on a defined cadence, with mechanisms to identify changes in roles and permissions. Access for separated employees is terminated via an automated deprovisioning checklist.
  • Endpoint controls: access requires Ycrest-issued laptops with disk encryption and endpoint detection and response (EDR) tooling that monitors and alerts on suspicious activity and malicious code.
  1. Monitoring & logging

User logging. Ycrest captures logs of certain activities within customer accounts and makes those logs available via API for your own analysis.

Infrastructure logging. Monitoring tools covering network, cloud environments, and identity solutions log activity in the production environment. Logs are monitored, analyzed for anomalies, and retained for at least one year.

  1. Vulnerability management
  • Penetration testing: independent third parties test the Services at least annually.
  • Vulnerability scanning: the production environment is scanned at least daily using up-to-date vulnerability databases, alongside regular dependency scanning of our codebase.
  • Patching: security patches are applied promptly; critical vulnerabilities in production dependencies are addressed within 24 hours of disclosure.
  • Workload protection: antivirus, anti-malware, and security detection tools monitor the production environment and alert on suspicious activity or potentially malicious code.
  • Bug bounty: ongoing security testing by independent researchers through our responsible disclosure and bug bounty program (see below).
  1. Incident detection & response

We maintain an incident response plan with defined roles and escalation paths.

If Ycrest becomes aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data (a "Security Incident"), we will notify you without undue delay, and no later than 72 hours after discovery — consistent with applicable regulations, including GDPR.

Investigation. We promptly take commercially reasonable steps to contain, investigate, and mitigate any Security Incident. Logs relating to a Security Incident are preserved for at least one year.

Communication and cooperation. Our notification will provide timely information to the extent known — including the nature and consequences of the incident, mitigation and containment measures taken, investigation status, and the categories and approximate number of data subjects and records concerned — along with a Ycrest representative for further information. Communications regarding a Security Incident are not an acknowledgement of fault or liability.

  1. Business continuity & disaster recovery

The Services back up Customer Data at least daily. Ycrest maintains an industry-standard business continuity and disaster recovery plan (the "BCP"), designed to restore the Services in the event of a service failure. The BCP is tested and reviewed annually.

  1. People & vendors
  • Criminal background screening, employment and identity verification as part of hiring, performed in accordance with applicable laws.
  • All employees with access to Customer Data complete security awareness training covering the protection, security, and confidentiality of Customer Data.
  • Personnel sign confidentiality agreements and an information security policy.
  • A vendor risk management program ensures each vendor that processes Customer Data maintains security measures consistent with our commitments.
  1. Third-party integrations

When you connect a data source (CRM, call recording, email, and so on), Ycrest requests only the minimum OAuth scopes necessary. Credentials are stored encrypted and never logged in plaintext. You can revoke any connection at any time from your account settings.

  1. Customer audit rights

Customers assess Ycrest's compliance primarily through our security documentation (and, once issued, our SOC 2 Type II report). Where that isn't sufficient, and no more than once per year (unless required by applicable law), customers may audit Ycrest's compliance with its security obligations following at least 45 days' written notice.

Audits may involve customer third-party consultants not reasonably objected to by Ycrest, subject to appropriate confidentiality obligations. Ycrest provides reasonable assistance, cooperation, and access; audits must not disrupt Ycrest's business or access other customers' information. Except as required by law, scope, methodology, timing, and conditions are mutually agreed in advance.

  1. Responsible disclosure

If you discover a security vulnerability, please report it to security@ycrest.ai with a description of the issue, steps to reproduce, and the potential impact. We'll acknowledge your report within 48 hours and work with you toward a resolution.

We ask that you not publicly disclose the issue until we've had a reasonable opportunity to address it.

We do not take legal action against researchers who act in good faith.

  1. Questions

For security-related questions, or to request our security documentation for your vendor review process:

Ycrest, Inc. — Security Teamsecurity@ycrest.ai

Your team learns from every interaction. We make sure it never forgets.

EXPLORE

Why Ycrest

© 2026 Ycrest. All rights reserved.