Yellow Technologies logoYellow Technologies

Yellow Technologies LLC

Security Practices

Effective Date: August 29, 2026
Last Updated: September 9, 2026

This page summarizes how Yellow Technologies LLC approaches security for our website, client portal, and service engagements. It is informational and does not create a separate contractual SLA unless agreed in writing.

1. Payments

Card payments are processed by Stripe. We do not store full payment card numbers on our servers. Stripe is a PCI DSS Level 1 service provider.

2. Authentication and Access

  • Client and staff accounts use authenticated sessions
  • Admin and team roles are restricted; clients only see their own projects and billing data
  • We encourage strong unique passwords and will support additional controls when scoped into an engagement

3. Data Handling on Client Projects

  • Access to client systems is limited to what is needed for the scoped work
  • Credentials and secrets should be shared through agreed secure channels, not public chat
  • We document ownership and handover so systems remain operable after delivery

4. Infrastructure

The website and application are hosted on modern cloud infrastructure with TLS in transit. Application data is stored in a managed PostgreSQL database. We apply least-privilege access for production credentials.

5. Incident Response

If we become aware of a security incident affecting personal information we control, we will investigate promptly and notify affected clients as required by applicable law and our Privacy Policy.

6. Responsible Disclosure

If you believe you have found a vulnerability in our public website or portal, email legal@yellowtechnologies.tech with enough detail for us to reproduce the issue. Please do not access or modify client data, and allow reasonable time for remediation before public disclosure.

7. Contact

Yellow Technologies LLC
legal@yellowtechnologies.tech | hello@yellowtechnologies.tech
763 Verde Vista Ct, Elgin, IL 60123
Website: yellowtechnologies.tech