UNFLD

Trust & Security

Security at UNFLD

Security at UNFLD starts with a narrower promise: know what data a product needs, limit who and what can reach it, and make important actions traceable.

Core controls

Controls appropriate to the product, data, and deployment model

Data minimization

We collect and retain only the data required to operate the service, deliver contractual functionality, and satisfy regulatory obligations.

Access boundaries

Access controls are documented per product and deployment. Role restrictions, MFA, and access reviews are applied according to the system’s current architecture and contractual scope.

Traceable actions

Relevant security and authentication events are logged according to the product scope, architecture, and documented retention model.

Commercial review

Security documentation

Product-specific security documentation is available during commercial review. It identifies current controls, responsible parties, subprocessors, data locations, retention, incident channels, and known exceptions.

Product documentation

Product-specific security documentation is available during commercial review, identifying controls, data locations, and subprocessors.

Data encryption

Data is encrypted in transit using modern TLS configurations and encrypted at rest on underlying datastores.

Deployment options

Available isolation, regional-hosting, and retention options are confirmed during architecture review and recorded in the applicable order form.

Identity & access

Support for single sign-on (SSO), role-based access control (RBAC), and session timeouts where supported by the product.

Vulnerability triage

Automated dependency scanning and controlled release workflows are documented for the products and environments where they are enabled.

Incident response

Documented incident response workflows with escalation channels and notification commitments defined in enterprise agreements.

Compliance disclosures

Standing answers to vendor security review

The compliance repository holds our standing answers across 19 control domains: information security policy, access management, encryption, data residency, backup and continuity, incident response, and supply chain. It is published rather than sent on request.

Coordinated disclosure

Report suspected vulnerabilities

Report suspected vulnerabilities to security@unfld.com.br. We will confirm receipt, assess scope, and coordinate remediation and disclosure in good faith.