UnicoOS maintains a comprehensive, documented Information Security Policy (ISP) framework that has been fully operationalized across our multi-tenant SaaS architecture. This policy outlines the systemic administrative, technical, and physical safeguards implemented to protect client-permissioned financial data and system infrastructure from unauthorized access, disruption, or exposure.
Our operationalized procedures are structured around three core pillars to manage risk continuously:
Automated vulnerability scanning, code dependency checks, and continuous asset profiling within our unified cloud environment to detect potential security weaknesses or misconfigurations before they can be exploited.
Strict enforcement of Least Privilege access controls, end-to-end data encryption (AES-256 at rest and TLS 1.3 in transit), automated IP throttling, and isolated multi-tenant database partitioning to contain risks natively.
Real-time event logging and centralized log auditing for all data access requests, integrated with automated alert workflows that instantly flag anomalous network activity or unverified cross-account traffic to platform administrators.
This policy applies to:
| Classification | Description | Examples |
|---|---|---|
| Confidential | Highly sensitive โ restricted access only | Bank tokens, API secrets, user credentials, PII |
| Internal | Business use only | Customer records, invoices, financial data |
| Public | Safe for public disclosure | Marketing materials, public website content |
Security incidents: Unico@E1Unico.com | Response SLA: Critical issues within 24 hours
| Vendor | Purpose | Certification |
|---|---|---|
| Vercel | Application hosting & edge network | SOC 2 Type II Certified |
| Neon | PostgreSQL database | SOC 2 Type II Certified |
| Plaid | Bank account linking | PCI DSS, SOC 2 Certified |
| Stripe | Payment processing | PCI DSS Level 1 Certified |
| Twilio | SMS / Voice communications | SOC 2 Type II Certified |
| GitHub | Source code & version control | SOC 2 Type II Certified |
This Information Security Policy has been reviewed, approved, and is actively enforced across all E1 Unico Corporation platforms as of the effective date below.
Manuel Montemayor Jr., Founder & CEO
E1 Unico Corporation
Annual review โ June 2027