generated: '2026-07-26' method: searched probe: false url: https://www.yardi.com/company/cloud-security/ name: Yardi Cloud Security summary: >- Yardi has no branded trust portal — trust.yardi.com does not resolve and /trust, /security and /compliance all 404 on www.yardi.com, which is why the automated trust-centre probe recorded nothing. What it does have is a single substantive Cloud Security page, reachable only through the company sitemap, that names real certifications and audit cadences. That page is the trust surface, and it is recorded here because the certifications on it are specific and checkable rather than marketing adjectives. certifications: - SOC 2 (annual) - SOC 1 (biannual) - SSAE 18 - PCI - HIPAA - Sarbanes-Oxley - CSA STAR Level 2 - FIPS 140-2 (key management) controls: encryption_in_transit: Automatic TLS encryption with active session management; encrypted cookies validated against the database before each request. encryption_at_rest: Optional AES-256 database encryption available on request; keys managed in a FIPS 140-2 compliant system. access_control: SSO integration, granular multi-level user/group privileges, administrator-set password complexity and expiration, automated inactivity log-off. network: Intrusion Prevention Systems (IPS) and multiple firewalls. testing: Third-party penetration tests and audits by external security vendors, described as regular and ongoing. physical: 15 global data centres with 24/7 server-operations monitoring, biometric screening, video surveillance and on-premises personnel. monitoring: 24/7 system monitoring, disaster recovery. evidence: - source: https://www.yardi.com/company/cloud-security/ status: 200 keywords: [PCI, SSAE 18, Sarbanes-Oxley, HIPAA, SOC2, SOC1, CSA Star Level 2, FIPS140-2, AES256, penetration tests] quote: >- "Feel confident your Cloud solution complies with PCI, SSAE 18 and Sarbanes-Oxley regulations. Senior Living providers can rest assured with resident health data adhering to the latest HIPAA rules. Annual SOC2 and biannual SOC1 reports are provided to ensure compliance with SSAE18 and other accounting standards. The Yardi Coud is CSA Star Level 2 certified by the Cloud Security Alliance." misses: - {url: 'https://trust.yardi.com/', status: 000, note: does not resolve} - {url: 'https://www.yardi.com/trust/', status: 404} - {url: 'https://www.yardi.com/security/', status: 404} - {url: 'https://www.yardi.com/company/security/', status: 404} - {url: 'https://www.yardi.com/security-and-compliance/', status: 404} gaps: - No report request/download portal; SOC 1 and SOC 2 reports are described as "provided" but no request path is published. - No vulnerability disclosure policy, bug bounty or security.txt anywhere on the estate (see security/yardi-canada-vulnerability-disclosure — none found). - No Canadian data-residency statement, despite Voyager, Breeze, Elevate, Investor Portal, Resident Screening and EHR Interfaces each running an explicit Canada region on the status page. - No sub-processor list on the security page; a sub-processor page exists separately at https://www.yardi.com/about-us/legal/yardi-sub-processors.