Security

How we protect the systems we build and the data they hold.

Data isolation

  • For workloads that need it, each customer gets an isolated AWS account, database, and API
  • No cross-customer data access paths between isolated tenants
  • A breach in one tenant cannot reach another, the blast radius is contained
  • Isolation is provisioned automatically on signup, not hand-configured per customer

Encryption

  • All data encrypted at rest using AWS-managed keys (AES-256)
  • All data in transit encrypted via TLS 1.2+ (enforced at the load balancer and API layer)
  • S3 bucket encryption enforced by bucket policy, no unencrypted uploads accepted

Secrets management

  • Application secrets stored in AWS Secrets Manager, never in environment variables or code
  • Secrets rotated on a schedule; access logged via CloudTrail
  • No credentials committed to version control, enforced by pre-commit hooks and CI checks

Access control

  • AWS Cognito with MFA required for all customer-facing authentication
  • IAM roles follow least-privilege, no wildcards on production resources
  • Root account access disabled; all access via named IAM users with MFA
  • SCPs applied at the AWS Organization level to prevent privilege escalation

Audit logging

  • AWS CloudTrail enabled in all regions with multi-region trail and log file validation
  • Application-level audit events logged to CloudWatch Logs with 90-day retention
  • Logs are immutable, stored in a separate account with write-once policy

Availability and backups

  • DynamoDB Point-in-Time Recovery (PITR) enabled, restores to any second in the last 35 days
  • Weekly cross-account backup snapshots stored in a separate AWS account
  • Infrastructure defined as code (CDK), full environment can be reproduced from source control
  • Region: us-east-1 (enforced by SCP on Unnamed OU)

Compliance posture

Unnamed Corp is not currently SOC 2 certified. SOC 2 Type II is on our 12-month roadmap. We build with SOC 2 controls in mind from day one so that certification is an audit, not a rebuild.

We follow AWS Well-Architected Framework principles across all five pillars: operational excellence, security, reliability, performance efficiency, and cost optimization.

Subprocessors

We use the following third-party services in the operation of the platform. We notify customers of material subprocessor changes with at least 30 days notice.

SubprocessorPurposePrivacy policy
Amazon Web Services (AWS)Cloud infrastructure, compute, storage, database, email (SES)View
StripePayment processingView
Amazon CognitoUser authentication and MFAView
Google (Calendar / Meet)Discovery call scheduling and video conferencingView
PostHogProduct analytics (privacy-preserving, no PII in events)View
SentryError monitoringView

Vulnerability disclosure

We welcome good-faith security research. If you believe you have found a vulnerability in any Unnamed system, email security@theunnamed.dev with reproduction steps. We acknowledge reports within 2 business days, keep you informed as we triage and fix, and credit researchers who want it once the issue is resolved. Machine-readable details live in security.txt.

Research conducted under these rules is authorized under our Acceptable Use Policy, and we will not pursue legal action for it: make a good-faith effort to avoid privacy violations, data destruction, and service disruption; do not access or modify data that is not yours — use test accounts where possible; give us reasonable time to fix an issue before public disclosure; and do not run automated high-volume scanning, denial-of-service, physical, or social-engineering attacks.

Out of scope: vulnerabilities in third-party services (report those to the vendor), clickjacking on pages with no sensitive actions, missing security headers without a demonstrated impact, and findings from automated scanners without a proof of concept.

Security documentation

Request our full security packet, architecture diagrams, control mappings, and penetration test summaries.

Request security packet