Upvm
Security

Security is our foundation

Your data and your customers' data are protected by industry-standard encryption, access controls, and compliance practices.

Encryption at Rest & In Transit

All data encrypted with AES-256 at rest. TLS 1.3 for all communications. No exceptions.

License Secret Protection

License signing secrets are never stored in plaintext. HMAC-signed tokens prevent tampering.

Audit Logging

Every action is logged with timestamp, actor, IP, and payload. Immutable audit trail.

JWT Authentication

Access + refresh token pattern. Passwords hashed with Argon2id. OAuth support for Google/GitHub.

SOC 2 Compliance

We follow SOC 2 Type II controls. Annual audits by independent third-party firms.

Infrastructure Security

All infrastructure in isolated VPCs. Regular security patches, intrusion detection, DDoS protection.

Shared responsibility model

Security is a partnership. Here's what each side owns.

UPVM (us)

  • Infrastructure & network security
  • Data encryption & key management
  • Platform-level access controls
  • Third-party security audits
  • Incident response & monitoring

You

  • Managing your account credentials
  • Configuring product-level security
  • API key rotation & management
  • Compliance with applicable laws
  • User data handling per your privacy policy

Found a vulnerability?

We take security reports seriously. Contact our security team directly.