# Does yc-360 meet enterprise security and compliance standards?

yc-360 is a lightweight, incident-triggered diagnostic script built for secure production environments. It runs temporarily, collects artifacts using standard OS utilities, and terminates without leaving any persistent agent or runtime instrumentation. It does not open listening ports, expand privileges, or modify application behavior. Artifact transmission is optional and encrypted (AES-256 GCM with RSA key exchange). Designed around least-privilege and governance principles, yc-360 aligns with enterprise security and compliance requirements. For a detailed architectural and security review (including STRIDE analysis and data flow diagrams), download the full security document here (opens new window).