Security
Transport security, security headers, and Content-Security-Policy. No secrets in the frontend and no raw card storage. Contact forms open a mailto draft — they are not server-posted yet. Responsible disclosure: enterprise@yammet.tech.
This marketing site does not process payments or store customer credentials. Product lines that handle regulated data will publish control mappings (access, retention, audit) before production launch.
Report suspected vulnerabilities on yammet.tech to enterprise@yammet.tech. Include steps to reproduce and avoid accessing non-public data. We will acknowledge receipt and work a fix before any coordinated disclosure.