- Money never touches YUPiTi. Clients pay straight into your own accounts.
- No card numbers are stored. Tax IDs are kept to the last 4 digits.
- Every change is logged, and everything is backed up nightly.
- Found a problem? Email hello@yupiti.app. We fix first and thank you publicly if you want.
How YUPiTi is built
- No funds held. Payments are processed by Square, Stripe and the other providers you connect. YUPiTi records the payment; it never holds or moves the money.
- No card data. Card entry happens on the processor's own secure checkout, so card numbers never reach our servers.
- Encrypted in transit. Every page and API call is served over HTTPS with HSTS.
- Locked-down pages. Security headers block framing and content sniffing. Client portals are passcode-protected, and invoice lookups lock out after repeated wrong tries.
- Team roles. Separate logins with roles, and an activity log of who did what and when.
- Secrets stay secret. API keys live in the host's secret settings, where they can be used but not read back, and never in the code, the browser or a backup. The few read-only keys you can paste in are encrypted with AES-256-GCM using a master key that only exists in those secret settings.
- Sign in where you already are. When a provider supports it, you connect by signing in on their own site, so we never see your password. We only ask for read-only or restricted access, and we never accept full-access keys.
- Passwords and codes. Passwords are hashed with scrypt, compared in constant time, and sign-ins are rate-limited. Authenticator keys are encrypted. Sign-in codes expire in 10 minutes.
- Nightly backups with a tested restore.
- Least data, with time limits. We only keep what the Service needs, and every kind of data has a time limit (see section 9 of our Privacy Policy). A cleanup runs every night before the backup. Tax IDs are stored as the last 4 digits only, and IP addresses are cut down to the general area.
Keys and passwords you connect
We avoid holding your keys. When a provider offers it, you connect by signing in on that provider's own site (for example Square, Google, Microsoft, QuickBooks or your bank through Plaid), so YUPiTi never sees your password. Other keys go in your host's secret settings, where they can be used but not read back. The few read-only keys you can paste into YUPiTi (such as a Shopify or Stripe product key) are encrypted with AES-256 before they're saved, are never shown again, are left out of backups, and are deleted the moment you disconnect. We only accept read-only or restricted keys, never full-access ones.
AI and connected tools
As YUPiTi connects to AI assistants and other apps, each connection gets the smallest access it needs, starts read-only, and can be switched off by you at any time. Nothing sends money or messages without a human approving it.
Reporting a vulnerability
If you think you have found a security issue, email hello@yupiti.app with the details and steps to reproduce. Please give us a reasonable chance to fix it before sharing it publicly, and don't access other people's data, disrupt the Service, or run automated scans that affect real customers.
We will reply within 3 business days, keep you posted while we fix it, and credit you if you like. Our contact details are also published at /.well-known/security.txt.