Security, privacy & data handling at YouSource
This page is maintained by the YouSource team to answer common security and privacy questions about the YouSource sourcing, evaluation, and marketplace app. It is app-owned editable content and not an independent certification or audit report.
Authentication & access control
Sign-in is available with email and password or Google sign-in. Sessions are managed by our backend provider; passwords are never stored in plain text by the application.
Access to data inside the app is enforced by row-level access rules in the database. Buyers, sourcing specialists, customers, evaluators, suppliers, and admins each see only the records their role and assignments allow.
Roles & least privilege
Roles are stored in a dedicated table and assigned through a server-side function — the browser cannot grant itself elevated permissions. Administrative roles are never self-assigned at sign-up.
Tokens used by external evaluators or supplier questionnaires are not exposed to other users in the workspace; they are issued and validated server-side.
Hosting & infrastructure
YouSource runs on managed cloud infrastructure with HTTPS in transit. Database, authentication, file storage, and AI gateway services are operated by reputable providers under their respective security programs.
We do not claim independent SOC 2, ISO 27001, HIPAA, or PCI certification on this page. If you need formal compliance documentation, contact us so we can share what is currently available.
Data we collect & how it's used
We collect the information needed to operate the sourcing workflow: account profile, sourcing requests, supplier and candidate data, quotes, evaluations, messages, files, and usage events. AI features process this data only to produce results inside your workspace.
Files you upload are stored in named buckets and are readable only by users with a legitimate need (the document owner, admins, or — for shareable supplier links — the holder of a valid invitation token).
Subprocessors & integrations
We rely on a small set of providers to deliver the service, including our cloud database/auth provider, our AI gateway, and web-search/enrichment APIs used inside AI features. If you connect optional integrations (e.g. Firecrawl-backed search), those providers process the relevant requests.
Retention & deletion
Account, request, and marketplace data is retained while your account is active. You can request deletion of your account and associated personal data by contacting us at the address below; some operational logs may be retained for a limited period for security and accounting purposes.
Reporting a security issue
If you believe you have found a security vulnerability or a privacy concern, please report it to security@yousource.me. Please include steps to reproduce, the impact you observed, and any logs or screenshots. We will acknowledge your report and follow up with a remediation plan.
Shared responsibility: YouSource secures the platform and the data we host. Customers are responsible for protecting their own credentials, the devices they use to access the app, and the information they choose to upload or share with suppliers.
Last updated: August 2026