Trust & Security at Unistack
Version: 2.0
Our Commitment to Security
At Unistack Software Services - FZCO, we understand that our clients entrust us with their most sensitive data, intellectual property, and business-critical systems. Security is not an afterthought—it is embedded into every aspect of our operations, from how we write code to how we manage infrastructure.
This page outlines our security practices, technical controls, and organizational commitments to protect your data and ensure the integrity of our services.
1. Security-First Development Practices
We follow industry best practices throughout the software development lifecycle (SDLC) to minimize vulnerabilities and ensure code quality:
1.1 Secure Coding Standards
- Code Reviews: All code changes undergo mandatory peer review before merging into the main branch.
- Static Application Security Testing (SAST): Automated tools scan code for common vulnerabilities (e.g., OWASP Top 10) on every commit.
- Dependency Scanning: We use tools like Snyk and Dependabot to identify and remediate vulnerable third-party libraries.
- Secrets Management: API keys, passwords, and credentials are never hardcoded. We use secure vaults (e.g., AWS Secrets Manager, HashiCorp Vault) for secrets storage.
1.2 Environment Separation
- Development, Staging, and Production: We maintain strict separation between environments. Production data is never used in development or testing.
- Synthetic Data: When realistic data is needed for testing, we use synthetic or anonymized datasets.
- Access Controls: Production environments are accessible only to authorized personnel through secure, audited channels.
1.3 Continuous Integration / Continuous Deployment (CI/CD)
- All deployments are automated through CI/CD pipelines (e.g., GitHub Actions, GitLab CI).
- Automated tests (unit, integration, security) must pass before deployment.
- Rollback procedures are documented and tested.
2. Infrastructure and Cloud Security
We leverage leading cloud providers with robust security certifications and implement additional controls to protect your data:
2.1 Cloud Providers
- Amazon Web Services (AWS): Our primary cloud infrastructure is hosted on AWS, which maintains ISO 27001, SOC 2 Type II, and PCI DSS certifications.
- Data Residency: We offer data residency options in the EU (Frankfurt) and UAE to comply with local data protection laws.
2.2 Encryption
- In Transit: All data transmitted over public networks is encrypted using TLS 1.2 or higher.
- At Rest: Data stored in cloud environments is encrypted using AES-256 or equivalent industry-standard algorithms.
- Key Management: Encryption keys are managed through secure key management services (e.g., AWS KMS).
2.3 Network Security
- Firewalls and Security Groups: Network access is restricted using firewalls and security groups with the principle of least privilege.
- DDoS Protection: We utilize cloud-native DDoS protection services (e.g., AWS Shield).
- Web Application Firewall (WAF): WAF rules are configured to protect against common web exploits.
3. Access Control and Authentication
We enforce strict access controls to ensure that only authorized personnel can access your data:
3.1 Role-Based Access Control (RBAC)
- Access to systems and data is granted based on the principle of least privilege.
- Roles are defined and reviewed regularly to ensure appropriate access levels.
3.2 Multi-Factor Authentication (MFA)
- Mandatory MFA: All employees and contractors must use multi-factor authentication to access internal systems, cloud consoles, and communication platforms.
- Hardware Keys: For privileged access (e.g., production databases), hardware security keys (e.g., YubiKey) are required.
3.3 Access Reviews
- Access rights are reviewed quarterly and immediately revoked upon employee termination or role change.
- Privileged access (e.g., database administrators) is logged and audited.
4. Incident Response and Breach Notification
We maintain a formal Incident Response Plan (IRP) to detect, respond to, and recover from security incidents:
4.1 Detection and Monitoring
- Logging and Monitoring: Security events are logged and monitored in real-time using centralized logging solutions (e.g., AWS CloudTrail, Datadog).
- Alerting: Automated alerts are configured for suspicious activities (e.g., unusual login attempts, unauthorized access).
4.2 Incident Response Process
- Detection: Security incidents are identified through monitoring, employee reports, or third-party notifications.
- Triage: The incident is assessed for severity and potential impact.
- Containment: Immediate actions are taken to contain the incident and prevent further damage.
- Investigation: Root cause analysis is conducted to understand the scope and impact.
- Remediation: Vulnerabilities are patched, and affected systems are restored.
- Post-Incident Review: Lessons learned are documented, and processes are improved.
4.3 Breach Notification
- In the event of a Personal Data Breach, we will notify the affected client without undue delay, and in any event within forty-eight (48) hours of becoming aware of the breach.
- Notification will include: the nature of the breach, categories of data/subjects affected, likely consequences, and measures taken to mitigate the breach.
- We will fully cooperate with the client in investigating and remedying the breach, and in notifying relevant supervisory authorities and data subjects as required by law.
5. Business Continuity and Disaster Recovery
We ensure that our services remain available and your data remains protected even in the event of an outage or disaster:
5.1 Backups
- Automated Backups: Critical systems and code repositories are backed up automatically on a daily basis.
- Retention Period: Backups are retained for 30 days (configurable based on client requirements).
- Encryption: All backups are encrypted at rest and in transit.
5.2 Disaster Recovery Plan (DRP)
- A documented Disaster Recovery Plan (DRP) is maintained and tested annually.
- Recovery Time Objective (RTO): We aim to restore critical services within 24 hours of a disaster.
- Recovery Point Objective (RPO): Data loss is limited to 24 hours (based on daily backups).
5.3 High Availability
- For clients requiring high availability, we offer multi-region deployments and load balancing to ensure service continuity.
6. Personnel Security
Our people are our first line of defense. We implement the following measures to ensure that all personnel are trustworthy and security-aware:
6.1 Background Checks
- Background checks are conducted for all employees prior to hiring, in compliance with local laws.
6.2 Security Training
- Mandatory Training: All employees undergo data protection and security awareness training upon hiring and annually thereafter.
- Phishing Simulations: Regular phishing simulations are conducted to test and improve employee vigilance.
6.3 Confidentiality Agreements
- All employees and contractors sign confidentiality agreements (NDAs) that survive termination of employment.
7. Compliance and Certifications
We are committed to complying with applicable laws and industry standards:
7.1 Current Status
- ISO 27001: We are currently working towards ISO 27001 certification. In the interim, we align our practices with ISO 27001 controls.
- SOC 2: We are planning to undergo a SOC 2 Type II audit in the future.
- GDPR: We comply with the EU General Data Protection Regulation (GDPR) for clients in the European Economic Area (EEA).
- UAE PDPL: We comply with the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data.
7.2 Client-Specific Requirements
- If your organization requires specific certifications or compliance attestations, please contact us to discuss your requirements. We are open to working with you to meet your compliance needs.
8. Audit Rights
We believe in transparency and accountability:
- Right to Audit: Clients have the right to audit our compliance with this Trust & Security page and our Data Processing Agreement (DPA), upon thirty (30) days' prior written notice and no more than once per calendar year.
- Third-Party Reports: To minimize business disruption, we may satisfy audit requests by providing recent third-party audit reports (e.g., SOC 2, ISO 27001) or by completing your organization's standard security questionnaire.
9. Sub-processors and Vendor Management
We carefully select and manage our sub-processors to ensure they meet our security standards:
- Sub-processor List: A current list of our authorized sub-processors is available at: https://getunistack.com/legal/sub-processors.
- Due Diligence: We conduct security due diligence on all sub-processors before engaging them.
- Contractual Obligations: All sub-processors are contractually obligated to maintain security standards no less protective than those described in this page.
10. Responsible Disclosure
We welcome security research and responsible disclosure of vulnerabilities:
- Security Contact: If you discover a security vulnerability, please contact us at: security@getunistack.com.
- Response Commitment: We will acknowledge receipt of your report within 3 business days and provide an initial assessment within 10 business days.
- Good Faith: We will not take legal action against researchers who disclose vulnerabilities in good faith and in accordance with this policy.
11. Changes to This Page
We may update this Trust & Security page from time to time to reflect changes in our practices or applicable laws. We will notify clients of material changes via email or through our website.
12. Contact Us
If you have any questions or concerns about our security practices, please contact us:
Email: security@getunistack.com
Address: Unistack Software Services - FZCO, IFZA Business Park, DDP, PO Box 342001, Dubai, UAE
This page describes UNISTACK's baseline internal security approach. Project-specific controls, hosting model, audit support, backup scope, incident notification timelines, RTO/RPO, data residency, and regulatory requirements are confirmed in the applicable Service Agreement, DPA, SOW, or Security Addendum.