Yandex takes data security very seriously and follows rigorous data protection rules to ensure our users' data is secure and their privacy is protected. All data is processed automatically in our system, and we prohibit access to the data by any individual other than in times of necessity such as for Yandex customer support or other obligatory administrative and technical help. We also always encrypt all stored confidential information, such as passwords.
Our technological infrastructure securely protects the data that we handle. We implemented a secure HTTPS protocol for all Yandex services, meaning all data is encrypted as it moves between the user and Yandex. We also integrated special protection measures where security is particularly important, such as processing online payments according to the international PCI DSS security standard.
Yandex ID provides unified authentication on all Yandex services and is pivotal to ensuring the security of user data. All data on Yandex ID is securely protected, which is confirmed by regular checks and independent auditors. Each year since 2020, Yandex ID is independently audited according to the SSAE 18 standard overseen by the American Institute of Certified Public Accountants (AICPA) and receives a Service Organization Control (SOC) 2 report certifying that it meets international security standards.
All Yandex services are tested according to the Data Protection Impact Assessment (DPIA) procedure. Compliance specialists look at how user data is handled on each Yandex service and make sure that all processes comply with international standards for information protection and risk management — ISO 27000 and ISO 31000. In order to prevent data leakage, the services regularly undergo mandatory external audits according to AICPA criteria. Any uncovered data breach is publicly disclosed by Yandex and followed by an internal investigation. To ensure that each Yandex employee understands their responsibility when working with data, all Yandex employees take mandatory courses on information security, corporate ethics, and confidential data protection.
Yandex encourages community-based cyber security research to further enhance data protection on its services. Since 2012, the company has been running a vulnerability reward program, The Yandex Bug Bounty, that honors external contributors for reporting vulnerabilities in Yandex’s security system. Yandex understands all potential risks associated with vulnerability research, which may involve getting access to sensitive or confidential information. The company ensures that the program participants are protected from litigation and provides them with assistance in case of third-party litigation, so long as they comply with the terms and conditions of the program.