ISO 27001 & SOC 2 aligned
Internal controls calibrated against ISO 27001/27002 and SOC 2 Type II criteria, on certified AWS infrastructure.
Security & Compliance
Comprehensive compliance disclosures, Information Security Policy (PSSI), ISO 27001/27002 controls, GDPR/LGPD alignment, and infrastructure architecture across UNFLD products and engineering operations.
AES-256
At rest, every tier
FileVault · RDS · S3
TLS 1.3
In transit, enforced
HTTP redirected to HTTPS
< 4h
Recovery time objective
RPO under one hour
11×9
Backup durability
Multi-AZ, WORM locked

What we hold ourselves to
Internal controls calibrated against ISO 27001/27002 and SOC 2 Type II criteria, on certified AWS infrastructure.
European workloads in Frankfurt and Ireland, LATAM workloads in São Paulo. GDPR and LGPD alignment throughout.
AES-256 at rest across databases, object storage, and snapshots. TLS 1.3/1.2 for every connection in transit.
SAML 2.0, OAuth 2.0, and OpenID Connect federation with multi-factor authentication mandatory for privileged access.
S3 Object Lock snapshots that cannot be deleted or altered, validated by quarterly restoration drills.
Dependency and static analysis on every pull request, monthly system scans, and periodic external penetration tests.
The repository
Everything a vendor risk assessment asks for, grouped the way a reviewer reads it — from the policy at the top to the pipeline that ships the code. Search below to jump straight to an answer.
Search every disclosure
Filter 98 answers across 19 control domains.
The Information Security Policy that everything else hangs from — how it is validated, reviewed, audited, and held against ISO 27001, SOC 2, GDPR, and LGPD.
The ledger
UNFLD runs lean. Rather than claim accreditations we do not hold, we state precisely where a certificate exists and where we calibrate our own practice to the criteria.
Who can reach what, proven at every boundary. Least privilege, documented identity lifecycle, enforced multi-factor authentication, and enterprise federation.
Federated by default
Enterprise tenants federate through SAML 2.0, OAuth 2.0, or OpenID Connect against Microsoft Entra ID, Okta, or Google Workspace. When someone leaves your organisation, they leave ours in the same moment — no parallel account list to reconcile.

Where the compute physically sits, how the network is cut into segments, and what stands between the public internet and a database.
Data residency
EU primary
eu-central-1
Frankfurt · Germany
GDPR-resident workloads and encrypted RDS instances.
EU secondary
eu-west-1
Dublin · Ireland
Cross-region replication target for European clients.
LATAM primary
sa-east-1
São Paulo · Brazil
Local residency for Brazilian and LGPD-governed data.
Edge delivery and DDoS mitigation through Cloudflare points of presence worldwide. Origin compute never leaves the contracted region.
The day-to-day: hardened workstations, change control, log aggregation, and what happens in the hours after something goes wrong.
When something goes wrong
An incident is not the moment to invent a process. Triage, containment, root cause, and notification are written down before we ever need them.
Breach notification follows GDPR, LGPD, and contractual SLA terms — investigated and communicated to affected parties and regulators without undue delay. Everything an investigation needs is already being retained.
12 mo
Log retention
24–72h
Critical patch window
90 days
Snapshot retention
Classification, encryption, immutable snapshots, and the recovery objectives we hold ourselves to when a region goes dark.
Enforced, not aspirational
Encryption, credential handling, and retention are not a policy document somebody remembers to apply. They are the defaults every UNFLD environment is provisioned with, and drift from them fails the pipeline.
posture.yml
# posture.yml — enforced across every UNFLD environmenttransport: minimum: "TLS 1.2" preferred: "TLS 1.3" plaintext_http: "redirect" # never served at_rest: workstations: "FileVault AES-XTS" databases: "AWS RDS AES-256" objects: "S3 SSE-KMS AES-256" backups: "AES-256 + S3 Object Lock" credentials: hashing: "Argon2id, bcrypt fallback" admin_mfa: "required" # TOTP or hardware key federation: ["SAML 2.0", "OAuth 2.0", "OIDC"] retention: operational_logs: "12 months" database_snapshots: "90 days" archives: "monthly + yearly point-in-time"How software gets built and reviewed before it ships, how tenants stay separated, and what we require of every vendor we bring in.
Before anything ships
01
Every pull request needs a human reviewer. No exceptions, no self-merge to production branches.
02
Static analysis, dependency scanning, and secret detection run on each commit before a merge is possible.
03
Infrastructure and application changes reach staging first, under the same encryption and access controls.
04
Penetration tests and vulnerability assessments with outside specialists, remediated by severity.
Security reviews & enterprise audits
Our legal and security engineering team in São Paulo provides custom vendor questionnaires, SOC 2 alignment mappings, Data Processing Addenda, and architectural reviews for enterprise partners.
security@unfld.com.br · sales@unfld.com.br