Security approach

Security requirements differ by product, deployment model and customer. We define the controls, responsibilities and operating boundaries for each engagement instead of making one blanket claim for every system.

Secure development

Our delivery process considers architecture, data flows, authentication, authorization, secrets, dependencies and deployment controls from the start. Reviews and release checks are matched to the risk and scope of the system being delivered.

Tenant and data isolation

Multi-tenant systems are designed to enforce tenant context and authorization at trusted application and data boundaries. Customer-specific deployments can use separate projects, databases or infrastructure where the agreed risk model requires stronger isolation.

Access and auditability

Products use role-based access and least-privilege principles. Administrative actions, approvals and material workflow changes are made auditable where the product's operating model requires them.

Backup and recovery

Backup schedules, retention, restore procedures and ownership are defined for each hosted or customer-managed deployment. Recovery objectives are documented in the applicable project or service agreement rather than assumed to be universal.

Data ownership and privacy

Customers retain ownership of their operational data. We minimize access to production data, separate environments where appropriate and use customer information only to deliver and support the agreed service.

Compliance

WeuniOs does not present a company-wide certification that it has not obtained. Regulatory, residency and assurance requirements are assessed with each customer and reflected in the solution architecture and contract when they apply.

Have a security requirement? Discuss it with us.