Security approach
Security requirements differ by product, deployment model and customer. We define the controls, responsibilities and operating boundaries for each engagement instead of making one blanket claim for every system.
Secure development
Our delivery process considers architecture, data flows, authentication, authorization, secrets, dependencies and deployment controls from the start. Reviews and release checks are matched to the risk and scope of the system being delivered.
Tenant and data isolation
Multi-tenant systems are designed to enforce tenant context and authorization at trusted application and data boundaries. Customer-specific deployments can use separate projects, databases or infrastructure where the agreed risk model requires stronger isolation.
Access and auditability
Products use role-based access and least-privilege principles. Administrative actions, approvals and material workflow changes are made auditable where the product's operating model requires them.
Backup and recovery
Backup schedules, retention, restore procedures and ownership are defined for each hosted or customer-managed deployment. Recovery objectives are documented in the applicable project or service agreement rather than assumed to be universal.
Data ownership and privacy
Customers retain ownership of their operational data. We minimize access to production data, separate environments where appropriate and use customer information only to deliver and support the agreed service.
Compliance
WeuniOs does not present a company-wide certification that it has not obtained. Regulatory, residency and assurance requirements are assessed with each customer and reflected in the solution architecture and contract when they apply.
Have a security requirement? Discuss it with us.