Trust Centre · draft

A clearer trust boundary.

Yabby is a CNAME reverse proxy. It necessarily has transient visibility of requests and responses required to serve the page, while the MVP stores only bounded aggregate signals. This Trust Centre separates operating controls from customer responsibilities and legal drafts.

What Yabby controls

  • The Worker request path, exact public-hostname-to-origin mapping, and rejection of unknown site configuration.
  • Qualifying-navigation rules, sensitive-path canonicalisation, 30-day aggregate rollups, durable k=5 breakdown thresholds, and Durable Object retention cleanup.
  • Experiment validation: one active experiment per site, exact paths, anchor-only selectors, fixed 50/50 allocation, signed same-origin redirects, daily assignment-cookie expiry, and private/no-store transformed responses.
  • Access and CSRF protection on administrative mutations, strict allowlists for platform signals and appearance presets, and no raw event store.

What the customer controls

  • Whether to delegate a hostname to Yabby, which pages and data flows are in scope, and the DNS rollback path.
  • Origin firewall, authentication, CDN/WAF chain, cache policy, cookies, CSP, application permissions, and whether the origin remains directly reachable.
  • Their privacy notices, lawful basis or consent decisions, data-subject response process, retention instructions, and legal review.
  • Who may deploy or administer the customer’s Cloudflare, origin, DNS, analytics, and consent systems.

Pilot security gates

  • The lab deployment uses Cloudflare IPv4/IPv6 network allowlisting, signed origin headers, and a fail-closed WordPress validator; per-site secret management and customer-hosting variants remain rollout work.
  • Use a marketing or staging hostname with no checkout, account, payment, admin, internal, or customer-sensitive content until qualification passes.
  • Give the customer an independent DNS bypass and rehearse origin degradation, direct-origin attempts, malformed configuration, cache/Host confusion, and analytics-write failure.
  • Treat Cloudflare role separation, deployment review, audit evidence, secret rotation, and a written incident/support owner as production gates. Current evidence is incomplete.

Current non-goals

  • No claim of GDPR, CCPA/CPRA, APP, COPPA, PIPEDA, HIPAA, or other legal compliance by the implementation alone.
  • No IP or hashed-IP identity, sessions, unique visitors, cross-site identity, raw referrers, raw user-agent storage, or purchase attribution.
  • No HIPAA-covered processing in the MVP. Do not send protected health information until a separately reviewed service and signed agreement exist.