๐Ÿข

E1 Unico Corporation

Information Security Policy
Effective Date: June 2026  |  Version: 1.0  |  Classification: Internal / Regulatory
Policy Owner: Manuel Montemayor Jr., Founder & CEO
Contact: Unico@E1Unico.com  |  1 (833) 318-6426  |  e1unico.com
BBB Accredited Business

Executive Policy Statement

UnicoOS maintains a comprehensive, documented Information Security Policy (ISP) framework that has been fully operationalized across our multi-tenant SaaS architecture. This policy outlines the systemic administrative, technical, and physical safeguards implemented to protect client-permissioned financial data and system infrastructure from unauthorized access, disruption, or exposure.

Our operationalized procedures are structured around three core pillars to manage risk continuously:

๐Ÿ” Identification

Automated vulnerability scanning, code dependency checks, and continuous asset profiling within our unified cloud environment to detect potential security weaknesses or misconfigurations before they can be exploited.

๐Ÿ›ก๏ธ Mitigation

Strict enforcement of Least Privilege access controls, end-to-end data encryption (AES-256 at rest and TLS 1.3 in transit), automated IP throttling, and isolated multi-tenant database partitioning to contain risks natively.

๐Ÿ“ก Monitoring

Real-time event logging and centralized log auditing for all data access requests, integrated with automated alert workflows that instantly flag anomalous network activity or unverified cross-account traffic to platform administrators.

1. Scope & Applicability

This policy applies to:

2. Data Classification

ClassificationDescriptionExamples
ConfidentialHighly sensitive โ€” restricted access onlyBank tokens, API secrets, user credentials, PII
InternalBusiness use onlyCustomer records, invoices, financial data
PublicSafe for public disclosureMarketing materials, public website content

3. Access Control

4. Financial Data & Plaid Integration Security

4.1 Plaid Bank Account Linking

4.2 Stripe Payment Processing

5. Technical Security Controls

5.1 Encryption Standards

5.2 Application Security

5.3 Infrastructure Security

6. Monitoring & Incident Response

6.1 Continuous Monitoring

6.2 Incident Response Procedure

  1. Detect & Contain โ€” Identify the incident and isolate affected systems within 1 hour
  2. Assess โ€” Determine scope, affected data, and potential impact
  3. Notify โ€” Inform affected customers within 72 hours per applicable law and Plaid policy
  4. Remediate โ€” Patch vulnerabilities, rotate credentials, restore services
  5. Review โ€” Conduct post-incident review and update policy within 30 days

Security incidents: Unico@E1Unico.com | Response SLA: Critical issues within 24 hours

7. Authorized Subprocessors

VendorPurposeCertification
VercelApplication hosting & edge networkSOC 2 Type II Certified
NeonPostgreSQL databaseSOC 2 Type II Certified
PlaidBank account linkingPCI DSS, SOC 2 Certified
StripePayment processingPCI DSS Level 1 Certified
TwilioSMS / Voice communicationsSOC 2 Type II Certified
GitHubSource code & version controlSOC 2 Type II Certified

8. Compliance Framework

Policy Approval

This Information Security Policy has been reviewed, approved, and is actively enforced across all E1 Unico Corporation platforms as of the effective date below.

Manuel Montemayor Jr., Founder & CEO
E1 Unico Corporation

Annual review โ€” June 2027