Security
Last updated 9 September 2026
What protects the work you put into yeses, where the deliberate trade-off is, and which things do not exist yet.
The reviewer link is the credential
This is the decision worth understanding before anything else, because it is the one that trades security for the product working at all.
A reviewer approves from a link, with no account and no password. That link carries 256 bits of randomness from a cryptographic generator, which is long enough that guessing is not a realistic attack. But whoever holds the link can decide as the reviewer it belongs to. A forwarded link is the risk, not a guessed one.
That is deliberate. An executive who has to create an account is an executive who does not review anything. If a link goes somewhere it should not have, you can reset it, which invalidates the old one and sends the reviewer a new one.
Accounts and sign-in
Sign-in is handled by Clerk. yeses never sees or stores a password, and you can use whichever sign-in methods Clerk offers you. Organization membership decides what you can see, and only an organization admin can change connections or close an organization.
In transit and at rest
Everything travels over TLS. Nothing about yeses is served over plain HTTP. Your projects, files and approval history are stored by Convex, and uploaded files are reachable only through the product or through a reviewer's link, never from a public address you could guess.
Our providers are listed on the privacy page, and they are based in the United States, so using yeses means data is transferred there.
The Slack connection
Connecting Slack stores an access token for your workspace. It is held server side, is never returned to a browser, and no part of the product displays it. Disconnecting deletes it and tells Slack to revoke it.
- The install uses a single-use state value with a thirty minute expiry, which is what stops somebody else's install being completed against your organization
- Four permissions are requested and no more. What each one is for is written out on the Slack page
- yeses cannot read your Slack messages, and asks for no permission that would let it
- Channel posts never carry a reviewer's email address and never carry a review link, because a channel is a wider audience than the person the link belongs to
What a connected workspace stores, and what happens to it afterwards, is set out on the privacy page.
The Figma connection
Connecting Figma stores an access token and a refresh token for your own Figma account, not your organization's. Both are held server side, never returned to a browser, and no part of the product displays them. Disconnecting deletes yeses's copy, but Figma gives us no way to revoke it on their end — remove yeses.io under Settings › Security in Figma yourself if you want that too.
- The connection is per person. There is no organization-wide Figma connection, and no admin control over it
- Two permissions are requested and no more: reading the files you choose, and reading who you are on Figma. What each is for is written out on the Figma page
- yeses never writes to a Figma file. It only ever reads the frames you pick
- Nothing about your reviewers touches Figma. Unlike Slack, no reviewer's email address is ever sent there
What a connected account stores, and what happens to it afterwards, is set out on the privacy page.
What is not built yet
Said plainly, because a security page that implies more than exists is the worst kind. None of the following is available today:
- Single sign-on
- Advanced roles, permissions and guest access
- Custom retention periods and audit export
- A signed data processing agreement
These are the same items the pricing page lists as coming. If one of them is the thing standing between you and using yeses, write and say so, because that is the useful signal for what gets built next.
Reporting something
If you think you have found a vulnerability, email support@yeses.io and put the word security in the subject. A person reads it within two business days, and you will get a reply rather than silence.
There is no bug bounty. yeses is operated by one person, so what you get is a fast, direct answer rather than a programme. Please do not test against other people's organizations or reviewer links.