SECURITY STATEMENT
Security at UniCo
Data Protection
UniCo Solutions separates account identity, owner-only private profile data and business data belonging to each Workspace. My Space and Business Space do not mix data automatically, and data classification never grants access by itself.
The Platform applies data minimisation, explicit authorization boundaries and controlled database changes. Future Highly Sensitive modules require a dedicated threat model before launch.
Encryption
Data is protected in transit using HTTPS/TLS when it travels between the user, the UniCo Platform and its managed infrastructure.
Managed hosting and database infrastructure applies encryption to customer data at rest. This is infrastructure-level protection and is not presented as application-level encryption implemented by UniCo Solutions.
Authentication & Administrative Security
Authentication and session management are provided through managed authentication infrastructure. Passwords are protected using one-way password hashing and are not stored in readable form.
Protected routes verify the authenticated user before loading private application areas. Privileged application secrets remain within protected application processes, while infrastructure administration is controlled separately from ordinary UniCo user access.
User-facing MFA, session and device management, and leaked-password protection remain planned. MFA has not been verified across every privileged infrastructure service, so UniCo Solutions does not claim universal administrative MFA.
Access Control & Tenant Isolation
Workspace membership and permissions are verified by the application for protected operations. Database-level access controls provide an additional authorization boundary, with missing or unknown permissions denied by default.
Private profile data is owner-scoped and excluded from the limited identity information used for Workspace administration. A platform role alone does not grant access to another user’s private profile or Workspace business content.
Infrastructure Security
The UniCo Platform operates on managed hosting, authentication and database infrastructure under a shared-responsibility model. Infrastructure services protect their documented systems; UniCo Solutions remains responsible for application authorization, secure configuration, secret handling and data design.
Managed database infrastructure provides scheduled backups. UniCo Solutions also uses controlled database changes and backup checkpoints, while final retention, point-in-time recovery configuration and restore-testing procedures remain operational hardening work.
Monitoring & Audit
The Workspace activity log records a defined subset of administrative events, including invitation, membership, role and module-access changes. Ordinary users cannot update or delete those records through the application.
This activity log is limited in scope and is not a universal security event system. Broader authentication-event coverage, centralized alerting and a formal incident-response process remain planned.
Security Development & Continuous Hardening
- Security-sensitive changes are reviewed with automated tests, production builds, controlled database changes and repeatable authorization and isolation checks.
- Next priorities include leaked-password protection, user MFA, session and device controls, security alerts and expanded activity logging.
- Future sensitive modules will add threat-led encryption, retention and recovery controls only where their data classification and risk justify them.
