Skip to content
Oyamu

Pre-launch policy library. Product policies are published for review; the waitlist is governed by its waitlist terms and privacy notice.

In brief

Good security is a shared effort. We use account and access safeguards; you can help by protecting your sign-in details and being careful about what you share. Spotted a problem? Here’s how to report it safely.

Protecting your information

Protecting information requires both technical safeguards and careful account use. No online service can eliminate every risk. This overview explains account protections and how to report a concern.

Specific security or service-level commitments for an organization are set out in its agreement.

Accounts and authorization

Oyamu’s protected app routes use authentication and permission checks to control access. The assistant route also applies request limits and origin checks.

Use a unique password or trusted sign-in method, protect your email account and sign out on shared devices. Organizations should grant only the access each person needs and remove access when it is no longer needed.

Data minimization and optional services

The website’s optional analytics and chat are controlled through Cookie settings. Marketing analytics disables session recording and automatic form capture, and diagnostic filtering removes several sensitive fields from handled errors.

Keep passwords, patient records and unnecessary private information out of study materials and AI prompts. Review a connected service and its permissions before enabling it.

Security and recovery information

Security, backup, location and recovery arrangements depend on the service and agreement. Contact us if you need information about a particular control or an organizational security requirement.

No specific restoration time or availability percentage is guaranteed unless expressly agreed.

Report a vulnerability

Email support@oyamu.com with “Security report,” the affected page or feature, what you observed and minimal reproduction steps. Remove secrets and personal information. Ask for a secure channel before sending sensitive evidence.

Use only systems and accounts you are authorized to access. Do not obtain other users’ records, extract data, disrupt service or continue testing when it creates a risk to others. Stop and report using the minimum evidence necessary.

This page does not authorize unrestricted testing or establish a bounty program.

Incident information and assistance

Report suspected account compromise or data exposure promptly. Notices and assistance concerning an incident are governed by applicable law and the relevant agreement.

For a security information request, contact support@oyamu.com with the service and information you need. See the Privacy policy for personal-information rights and the Data processing addendum for separately agreed organizational duties.

Contact Oyamu

Oyamu is operated by Oyamu LLC. For questions about this policy or your account, email support@oyamu.com. Include only what we need to understand your request. Do not send passwords, authentication codes or full payment-card details.

Security overview — Oyamu