Security is our foundation
Your data and your customers' data are protected by industry-standard encryption, access controls, and compliance practices.
Encryption at Rest & In Transit
All data encrypted with AES-256 at rest. TLS 1.3 for all communications. No exceptions.
License Secret Protection
License signing secrets are never stored in plaintext. HMAC-signed tokens prevent tampering.
Audit Logging
Every action is logged with timestamp, actor, IP, and payload. Immutable audit trail.
JWT Authentication
Access + refresh token pattern. Passwords hashed with Argon2id. OAuth support for Google/GitHub.
SOC 2 Compliance
We follow SOC 2 Type II controls. Annual audits by independent third-party firms.
Infrastructure Security
All infrastructure in isolated VPCs. Regular security patches, intrusion detection, DDoS protection.
Shared responsibility model
Security is a partnership. Here's what each side owns.
UPVM (us)
- Infrastructure & network security
- Data encryption & key management
- Platform-level access controls
- Third-party security audits
- Incident response & monitoring
You
- Managing your account credentials
- Configuring product-level security
- API key rotation & management
- Compliance with applicable laws
- User data handling per your privacy policy