Yohji — Security
Last reviewed: 2 October 2026
Yohji is built and run by one developer in Singapore. This page says plainly how your account and data are protected — and what hasn't been done yet.
How Yohji protects you
- HTTPS only. Every connection is encrypted, and browsers are told never to use plain HTTP for Yohji (HSTS).
- Your chats, messages, memory, projects and work data are encrypted at rest (AES-256-GCM) on Yohji's server, with the key kept outside the app and out of backups.
- Passwords are never stored as text — only a salted SHA-512 hash. If you sign in with Google or Apple, Yohji never sees a password at all.
- Sign-in protection: repeated wrong passwords or codes are blocked for a while, and you can turn on 2-step login codes and passkeys (fingerprint / face) in Settings → Account & sign-in.
- Every page needs a login, and each account only sees its own chats, memory and projects. Work files are shared only within your department, and Personal accounts can never see work data.
- Keys stay on the server, readable only by Yohji itself — never sent to your browser.
- Browser protections: Yohji's pages can't be framed by other sites (clickjacking), plugins are blocked, and browser features Yohji doesn't use (payments, USB, Bluetooth…) are switched off.
- The cloud browser and Shop for me only visit public websites, start empty every time, never log in and never type passwords or card numbers.
- Memory never keeps passwords, codes, card, bank or ID numbers — they're filtered out before anything is saved.
- Safe updates: every update is checked before it goes live and rolls itself back if Yohji doesn't start.
- No ads, no selling data. See the privacy policy.
What hasn't been done yet
Yohji has not had an independent security audit or penetration test. The protections above were reviewed by its developer. An outside audit is planned as Yohji grows.
Report a security problem
Found something? Please tell us privately: through the Yohji app (Messages → the owner). Include what you found and how to see it. You'll get a reply within 7 days.
Good-faith research is welcome: don't access or change other people's data, don't disrupt the service, and give us time to fix it before telling anyone. We won't take action against honest reports.