Built on trust

Security at Unmand

At Unmand, security has been a foundational focus from day one. We are continually working on new ways to ensure all data transmitted or stored is handled securely. Here are some of the ways we keep you and your data safe.

Visit our Trust Centre

Trusted by leading companies

Compliance

SOC 2

We are currently undergoing our SOC 2 Type I audit and are committed to meeting industry-recognised standards for security, availability, and confidentiality. For the latest status of our compliance program and to request documentation, visit our Trust Centre.

Product Security

Encryption

Unmand encrypts all customer data at rest with AES-256 encryption. Additional column level encryption is undertaken on sensitive customer data for an added layer of protection.

Session management

The location and IP address of each session is recorded, and you can revoke any sessions you don't recognise. Administrators can review all active sessions in the Unmand portal.

Secure connections

Unmand forces HTTPS for all services using TLS 1.2 or higher, including our public website and the customer portal. Unmand uses HSTS to ensure that all communications between your browsers and Unmand are encrypted.

Access and account controls

Access to data within Unmand's portal is governed by role and project-based controls and can be configured to define granular access privileges. There are permission levels for read, write and administrator.

Password and sensitive data

Unmand enforces a strong password policy. Passwords and other sensitive credentials are never stored in plain text; they are protected using a salted, one-way hashing algorithm.

Two factor authentication

To provide a second layer of security for your Unmand account, we support time-based one-time passwords (TOTP) using a compatible authenticator app such as Google Authenticator, Authy or 1Password. SMS-based one-time codes are also available.

Audit and logging

We maintain comprehensive logs of all activities and actions for each product. These logs can be used for your audit purposes or internally at Unmand for troubleshooting and support requests.

Physical Security

Infrastructure

Unmand's physical infrastructure is hosted and managed within Amazon's secure data centres using Amazon Web Services (AWS). All our production systems are physically located in Australia, unless otherwise stated in the sub-processor list on our Trust Centre. Amazon continually manages risk and undergoes recurring assessments to ensure compliance with industry standards. AWS's data centre operations are independently accredited under:
  • ISO 27001
    ISO 27001
  • SOC 2
    SOC 2
  • PCI
    PCI Level 1
  • FISMA Moderate+ Sarbanes-Oxley (SOX)+ more

These accreditations are held by AWS in respect of its data centres. See our Compliance section above for Unmand's own certification program.

Data Security

Data ownership

Your data 100% belongs to you. Unmand does not sell your data to third party providers. Unmand has a published privacy policy that clearly defines what data is collected and how it is used. We will never sell or transfer your data to a third party without your consent. For more information, see our Privacy Policy.

Data retention

You can control how long your data is retained. Retention periods are set out in the applicable product documentation and may vary by product, feature, and data type.

Data backups

Daily snapshots are retained for 30 days to support point-in-time recovery and are encrypted using AES-256 encryption. Backups are stored in a separate region from your production data, in line with your data residency requirements.

Data deletion

If your agreement with Unmand ends, we securely delete all customer data within 30 days. We maintain an offboarding register so that data belonging to offboarded customers is not reinstated when restoring from backup.

Sub-processors

Unmand maintains an up-to-date list of the third-party sub-processors we use to deliver our services. You can review our current sub-processors in our Trust Centre.

Resilience & Disaster Recovery

Resilient infrastructure

Our production environment runs across multiple, geographically separated data centres. If one location becomes unavailable, we are able to fail over to another region within your data residency boundary to keep services running.

Tested recovery

We test our backup restoration process at least annually to validate that data can be recovered reliably and within our recovery objectives.

Business continuity

We maintain a Business Continuity and Disaster Recovery plan covering service outages from events beyond our control. The plan is reviewed and formally tested at least annually.

Personnel Security

Background checks and access

Each team member undergoes a background check where permitted by applicable law, along with comprehensive training on data security protocols. Only a limited number of staff members can access customer data.

Confidentiality agreements

All employees and contractors are bound by non-disclosure and confidentiality agreements.

Security awareness training

Unmand provides staff with continuous communication on emerging threats, performs phishing awareness campaigns, and communicates with staff regularly.

Quality Controls

Peer code reviews

Every code release is reviewed by peers, whether it's a new feature or bug fix. Security reviews are performed as part of our software development sprint management and software dependencies are automatically scanned for vulnerabilities and security updates.

Continuous integration and delivery

Every code release is automatically subjected to a pipeline of rigorous tests and analysis before it is deployed. Our continuous deployment system and development process allow us to rapidly update and patch our system whenever needed.

Penetration testing and vulnerability scanning

We engage independent third parties to perform penetration testing of our products and infrastructure annually, and we run vulnerability scans quarterly. Findings are triaged and remediated according to their severity.

Vulnerability disclosure

We welcome reports of suspected security vulnerabilities. If you believe you have found a security issue in Unmand, please contact us at compliance@unmand.com and we will respond promptly.

Payment Security

Payment provider

Unmand uses Stripe for processing credit card payments. Stripe is certified to PCI Service Provider Level 1. This is the most stringent level of certification available in the payments industry.

Credit cards

Unmand does not store your credit card information. Credit card information is handled by Stripe with all card numbers encrypted at rest using AES-256. Decryption keys are stored on separate machines.