Data minimization
We collect and retain only the data required to operate the service, deliver contractual functionality, and satisfy regulatory obligations.
Trust & Security
Security at UNFLD starts with a narrower promise: know what data a product needs, limit who and what can reach it, and make important actions traceable.
Core controls
We collect and retain only the data required to operate the service, deliver contractual functionality, and satisfy regulatory obligations.
Access controls are documented per product and deployment. Role restrictions, MFA, and access reviews are applied according to the system’s current architecture and contractual scope.
Relevant security and authentication events are logged according to the product scope, architecture, and documented retention model.
Commercial review
Product-specific security documentation is available during commercial review. It identifies current controls, responsible parties, subprocessors, data locations, retention, incident channels, and known exceptions.
Product-specific security documentation is available during commercial review, identifying controls, data locations, and subprocessors.
Data is encrypted in transit using modern TLS configurations and encrypted at rest on underlying datastores.
Available isolation, regional-hosting, and retention options are confirmed during architecture review and recorded in the applicable order form.
Support for single sign-on (SSO), role-based access control (RBAC), and session timeouts where supported by the product.
Automated dependency scanning and controlled release workflows are documented for the products and environments where they are enabled.
Documented incident response workflows with escalation channels and notification commitments defined in enterprise agreements.
Compliance disclosures
The compliance repository holds our standing answers across 19 control domains: information security policy, access management, encryption, data residency, backup and continuity, incident response, and supply chain. It is published rather than sent on request.
Coordinated disclosure
Report suspected vulnerabilities to security@unfld.com.br. We will confirm receipt, assess scope, and coordinate remediation and disclosure in good faith.