Security and privacy
You trust Yesware with sensitive business data and rely on Yesware to be a responsible custodian of your clients' data as well. Yesware protects that data with independently audited controls, and its security posture is maintained to meet the standards expected across the industries you serve.
This page explains Yesware's approach at a high level. For security documentation, privacy policies, and reporting, contact support@yesware.com.
SOC 2® reporting
Yesware maintains a current System and Organization Controls (SOC 2®) Type 2 report, issued by an independent auditor.
A SOC 2 Type 2 report examines the design and operating effectiveness of an organization's controls over a defined period, measured against the Security Trust Services Criterion. It gives your own auditors and security teams the detail they need for vendor risk management.
The report itself is confidential and its use is restricted. Yesware shares it with you and others who need it for due diligence, typically under a non-disclosure agreement. Because the report is gated, this page does not reproduce its contents.
SOC 3® report
Yesware also makes a SOC 3® report available with no non-disclosure agreement required. Its content is largely identical to the SOC 2® Type 2 report, with the confidential, NDA-sensitive detail removed.
A SOC 3 report can only be issued alongside an unqualified SOC 2 Type 2 opinion, so its availability is itself evidence that Yesware passed the audit without exceptions.
For most vendor reviews, the SOC 3 report gives your security team everything it needs: independent confirmation that Yesware is SOC 2 Type 2 attested, without the wait or paperwork of a non-disclosure agreement. Request the SOC 3 report first. Reserve the full SOC 2 Type 2 report for cases where your vendor risk process specifically requires the detailed control testing it contains.
Request security documentation
When your security team needs to complete a vendor review, request access by contacting support@yesware.com:
- SOC 3 report – Available on request; no non-disclosure agreement required
- SOC 2 report – Available on request; access to gated documents may require a non-disclosure agreement
- Security control summary – The current, published summary of Yesware's controls
- Subprocessors – The current list of third-party subprocessors Yesware uses
For anything not covered here, contact support@yesware.com.
Privacy and data protection
Yesware's privacy practices govern how data is collected, processed, and protected across the platform. The following are available by contacting support@yesware.com:
- Customer Privacy Policy – How Yesware handles personal data
- Cookie Policy – How cookies and similar technologies are used
- California Privacy Rights – Disclosures for California residents
- GDPR – The data subject policy and procedure, and the personal data breach incident response procedure
Related settings
Several Yesware settings connect to how your data is secured and shared:
- Salesforce – Manage how email activity and data sync with your CRM
- BCC to CRM – Control how copies of your outgoing email are routed to your CRM