Security
Last updated: May 24, 2026
Security isn't a feature bolted on after the fact — it's how we're built. Yoseri is a portfolio-analytics platform for treating sports as an alternative asset class, so the data we hold is mostly your account details and your trading history. We treat all of it as sensitive. Here's exactly how we protect it.
Yoseri is not a broker
Yoseri never places positions, never holds your money, and never connects to your trading accounts. You place every position yourself, manually, at the broker or brokers of your choice. This is a security benefit, not just a design choice: because we hold no trading balances and no broker credentials, there is nothing of that kind for an attacker to reach through Yoseri. We are an analytics layer on top of your activity — never a custodian of your funds or your broker logins.
Infrastructure
Yoseri runs on hardened cloud infrastructure with network isolation, audit logging, and strict, least-privilege access controls. Encrypted, automated backups run daily and are retained for 30 days, with restore procedures tested regularly.
Data encryption
All data is encrypted at rest with AES-256 and in transit with TLS 1.3. Encryption keys are rotated regularly and stored in a hardened key-management service. Your data is unreadable to anyone without authorized access — including in the unlikely event of physical media compromise.
Authentication
Passwords are never stored in plain text — they are salted and hashed with a modern, slow hashing algorithm. Sessions are protected with secure, HTTP-only tokens, and sensitive account actions require re-authentication.
Payment security
Payments are processed by Stripe, certified PCI DSS Level 1 — the highest card-security standard in the industry. Yoseri never sees or stores your full card number; card data goes directly to Stripe and never touches our servers.
Coordinated disclosure
We operate a coordinated vulnerability disclosure program. If you believe you've found a security issue, email support@yoseri.com with details and steps to reproduce. We'll acknowledge your report, investigate promptly, and keep you updated through remediation. Please give us reasonable time to fix issues before any public disclosure.
Incident response
We maintain a documented incident-response process covering detection, containment, eradication, and recovery. If an incident ever affects your data, we will notify affected users without undue delay and in line with applicable law.
Compliance
Our encryption, payment security, and privacy controls are designed around the GDPR baseline. We run on infrastructure providers that maintain SOC 2 Type II attestations. For privacy details, see our Privacy Policy.
Security practices evolve continuously. This page describes our current controls and is updated as they change.