niCoSolutions
International policy baseline — product facts, legal requirements and planned capabilities are identified separately.

TRUST FOUNDATION

Trust & Compliance

A clear summary of UniCo Solutions’ verified application controls, managed safeguards, privacy framework and security architecture, with planned enhancements identified separately.
Implemented

Security controls in place

  • Connections to the UniCo Platform use HTTPS/TLS in transit, and managed hosting and database infrastructure encrypts customer data at rest.
  • Managed authentication infrastructure protects account access and sessions. Passwords are not stored in readable form.
  • Business and account data is protected by database-level access controls and application authorization checks.
  • Unknown or missing permissions are denied by default.
  • Business Workspace access requires active membership and is separated from other Workspaces.
  • Private personal profile details are owner-scoped and are not exposed through Workspace membership.
  • Privileged application secrets are restricted to protected application processes, and database changes follow a controlled, versioned process.
  • A defined subset of Workspace administration actions is recorded in the existing audit log.
Implemented

Access and context boundaries

A platform role alone does not grant access to private profile data or business content in a Workspace. Platform administration is limited to the metadata and actions explicitly authorized for it.

My Space and Business Space are separate contexts. UniCo Solutions does not automatically move, copy or mix data between them.

International privacy baseline

UniCo Solutions uses a global privacy notice with additional sections for the United Kingdom, EU/EEA, United States and California, Australia, and other jurisdictions. A right or duty applies only where the relevant law covers the user, operator or processing activity.

Privacy requests and complaints may be sent through the contact details published on the UniCo Home page. UniCo Solutions may verify identity and authority before protected information is disclosed or changed.

Architecture foundation

External Professional Access

Future access for accountants, auditors, lawyers, advisers and consultants will require explicit, narrowly scoped, expiring and revocable delegation. Personal and Business access will be granted separately.

This is an approved default-deny architecture direction, not an implemented product capability.

Planned hardening

Planned hardening

  • MFA/2FA and user-facing session or device management.
  • Leaked-password protection, appropriate rate limiting and CAPTCHA controls.
  • Expanded security audit coverage and security event notifications.
  • Operational privacy access, export, correction, retention and deletion workflows.
  • Formal incident-response, supplier-governance and compliance-evidence processes.