Security

Answers to frequently asked questions about the data protection and privacy of the Yandex AI Studio platform, as well as our approaches and best practices to ensure comprehensive security: from working with platform models and components to creating AI applications or agents.

Based on the Yandex Cloud platform

Yandex AI Studio components run on Yandex Cloud infrastructure and provide the same security circuit, access control, scaling, and compliance with corporate requirements.

Fault tolerance and availability

The AI Studio platform is deployed in several accessibility zones in the Russian Federation. This increases its efficiency and makes it possible to redistribute resources in response to changing loads.

The security you expect from our services

Do you store data in Object Storage, on virtual machines, or use DataLens? AI Studio uses the same safety circuit and mechanisms, so the level of protection remains the same.

ISO 42001

The level of protection has been independently tested for compliance with ISO 42001, confirming that our control mechanisms meet industry requirements for:

  • security,
  • confidentiality,
  • data availability.

To learn more about our security measures and compliance activities, please request access to the ISO 42001 report.

Key security principles

We provide customers with all the necessary information about the internal structure of AI Studio and existing processes, we conduct regular internal and external audits to assess the platform’s compliance with standards and requirements.

Compliance with standards

We are constantly improving information security processes and mechanisms for creating and operating our platform and its components in order to comply with federal and international standards.

Shared responsibility

We share the responsibility for ensuring security. Find out what the provider and customer are responsible for when creating AI applications and agents.

Data privacy

We pay special attention to data security, with storage in accordance with Russian legislation and international standards.

Default security tools

Additional security tools

Security monitoring

The Yandex Audit Trails service is responsible for it. It allows you to collect all user actions to work with platform components. Audit Trails for Yandex AI Studio supports event tracking at the configuration and service levels. There are events for setting up and triggering the moderation component.

Please note that user requests are not included in audit logs.

Guardrails

They allow users to flexibly control the admissibility of model requests and responses based on security policies, content categories, and created dictionaries.

  • The moderation model is a specially trained Yandex model.

  • Specialized dictionaries by type category for additional guarantees.

Additional insulation method

A dedicated network channel based on Yandex Cloud components:

  • Private endpoints

  • Yandex Cloud Interconnect

  • Yandex GOST Gateway

Public documents

Certificates of compliance with Federal Law No. 152-FZ, ISO standards, information on Yandex AI Studio’s inclusion in the Unified Russian Software Registry and other certificates are publicly available.
You can download these and other documents below.

Documents, available on request

Not all documents and regulations are freely available. Some of them contain sensitive information and are only available on request. Please fill out this short form. After checking the NDA, our specialists will send you a link to the document.

FAQ

The ISO/IEC 42001:2023 standard defines requirements for artificial intelligence management systems. Compliance with the standard helps organizations minimize AI-related risks, increase transparency and trust in AI solutions, optimize processes for developing and using AI, and ensure compliance with regulatory and ethical requirements.

Any questions?

If you have any questions about securing the platform, please email us or fill out the form below. We will advise you and help you come up with the best solution for your project.