niCoSolutions
International policy baseline — product facts, legal requirements and planned capabilities are identified separately.

SECURITY STATEMENT

Security at UniCo

UniCo Solutions applies technical and organisational measures designed to protect data processed through the UniCo Platform. Its safeguards combine verified application controls, managed infrastructure protection and continuous security review.
Implemented

Data Protection

UniCo Solutions separates account identity, owner-only private profile data and business data belonging to each Workspace. My Space and Business Space do not mix data automatically, and data classification never grants access by itself.

The Platform applies data minimisation, explicit authorization boundaries and controlled database changes. Future Highly Sensitive modules require a dedicated threat model before launch.

Implemented

Encryption

Data is protected in transit using HTTPS/TLS when it travels between the user, the UniCo Platform and its managed infrastructure.

Managed hosting and database infrastructure applies encryption to customer data at rest. This is infrastructure-level protection and is not presented as application-level encryption implemented by UniCo Solutions.

Implemented

Authentication & Administrative Security

Authentication and session management are provided through managed authentication infrastructure. Passwords are protected using one-way password hashing and are not stored in readable form.

Protected routes verify the authenticated user before loading private application areas. Privileged application secrets remain within protected application processes, while infrastructure administration is controlled separately from ordinary UniCo user access.

User-facing MFA, session and device management, and leaked-password protection remain planned. MFA has not been verified across every privileged infrastructure service, so UniCo Solutions does not claim universal administrative MFA.

Implemented

Access Control & Tenant Isolation

Workspace membership and permissions are verified by the application for protected operations. Database-level access controls provide an additional authorization boundary, with missing or unknown permissions denied by default.

Private profile data is owner-scoped and excluded from the limited identity information used for Workspace administration. A platform role alone does not grant access to another user’s private profile or Workspace business content.

Implemented

Infrastructure Security

The UniCo Platform operates on managed hosting, authentication and database infrastructure under a shared-responsibility model. Infrastructure services protect their documented systems; UniCo Solutions remains responsible for application authorization, secure configuration, secret handling and data design.

Managed database infrastructure provides scheduled backups. UniCo Solutions also uses controlled database changes and backup checkpoints, while final retention, point-in-time recovery configuration and restore-testing procedures remain operational hardening work.

Implemented

Monitoring & Audit

The Workspace activity log records a defined subset of administrative events, including invitation, membership, role and module-access changes. Ordinary users cannot update or delete those records through the application.

This activity log is limited in scope and is not a universal security event system. Broader authentication-event coverage, centralized alerting and a formal incident-response process remain planned.

Planned hardening

Security Development & Continuous Hardening

  • Security-sensitive changes are reviewed with automated tests, production builds, controlled database changes and repeatable authorization and isolation checks.
  • Next priorities include leaked-password protection, user MFA, session and device controls, security alerts and expanded activity logging.
  • Future sensitive modules will add threat-led encryption, retention and recovery controls only where their data classification and risk justify them.