Third Party Index

Snapshot 34461

Document
Security page
URL
https://www.unipile.com/security-compliance/
Fetched
HTTP status
200
Content type
text/html
Fetch mode
static
Size
124603 bytes
SHA-256 (raw)
3590701e21360364ec76a107fd12608e5bcad739a33ea6ff9db3bad99be44e93
SHA-256 (normalized text)
9756593c5b4437f6e61d6c516cc310d1f785fffc32ed3a9eb85dd9f22efea0f0

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Trust & Security
Your Data Deserves
Uncompromising Protection
We've built security into every layer of Unipile. SOC 2 Type II certified, GDPR compliant, with all data hosted exclusively in the European Union. Your communications are protected by enterprise-grade encryption.
Certified
SOC 2 Type II
CASA Tier 2
GDPR
Security Status
All Systems Secure
256-bit
Encryption
TLS1.3
In Transit
24/7
Monitoring
Data Encryption
AES-256 at rest, TLS 1.3 in transit
Active
Real-time Monitoring
Threat detection & alerting
Active
Access Control
SSO & MFA enforcement
Active
Certified
SOC 2 Type II
CASA Tier 2
GDPR
Built-In Protection at Every Layer
From data encryption to application security, we implement industry best practices to keep your communications safe.
Data Encryption
All data encrypted at rest (AES-256-GCM) and in transit (TLS). Keys managed securely via Scaleway Key Manager.
Infrastructure Security
Hosted exclusively on Scaleway datacenters in France. Full GDPR compliance with no data transfer outside EU.
Access Control
Least privilege principle enforced. Mandatory MFA for all internal tools and restricted production access.
Application Security
Systematic code reviews, protected branches, secure secrets management, and annual third-party penetration tests.
Compliance & Certifications
Audited by independent third-party firms. Meeting the highest standards of security and data protection.
Certification
Description
SOC 2 Type II Certified
Audited by independent third-party. Covers security, availability, and confidentiality trust service criteria.
GDPR Compliant
Full compliance with EU data protection regulations. Unipile acts as Data Processor. DPA available upon request.
CASA Tier II Certified
Google Cloud Application Security Assessment. Validated security controls for applications accessing Google user data.
All systems operational • No incidents reported
Data Privacy Features
Full control over your data. Choose where it's stored and maintain complete visibility on access.
Data Residency
Your Data Stays in France
All data is hosted exclusively in France on Scaleway datacenters. Full GDPR compliance with no data transfer outside the European Union.
France only – Data stored in French datacenters
Scaleway infrastructure – European cloud provider
No transfers outside EU – Full GDPR compliance
Data Location France (Scaleway)
Active
Audit & Logging
Complete Visibility & Control
Keep detailed records of all data processing activities. Full transparency for compliance audits and security monitoring.
Audit trail – Track all user actions in dashboard
Access logs – Monitor who accessed what data
Critical event journaling – Real-time monitoring
Monitoring Real-time Logs
Active
Internal Security Practices
Our team follows strict security protocols and best practices to protect your data from the inside out.
Employee Training
Regular security awareness training for all team members.
Background Checks
Security screening for all employees with data access. Immediate access revocation upon departure or role change.
Incident Response
24/7 monitoring with documented incident response procedures. Continuous supervision of metrics and logs with critical event journaling.
Physical Security
100% remote company with no on-premise servers. Physical security fully managed by Scaleway secure datacenters in France.
Need Our Security Documentation?
Get access to SOC 2 reports and DPA on demand.
SOC 2 DPA
Security FAQ
Common questions about our security practices, compliance certifications, and data protection measures.
All data is hosted exclusively in France on Scaleway datacenters, a European cloud provider. There are no on-premise servers and no data transfers outside the European Union, ensuring full GDPR compliance.
Yes, Unipile is SOC 2 Type II certified. This certification is audited by an independent third-party and covers security, availability, and confidentiality trust service criteria. You can request a copy of our SOC 2 report through our security documentation form.
We use enterprise-grade encryption at every level:
Data at rest: AES-256-GCM symmetric encryption via Scaleway Key Manager with built-in integrity verification (GCM tag)
Data in transit: TLS encryption for all communications
Asymmetric encryption: RSA-OAEP with 2048, 3072, or 4096-bit keys when required
Yes, Unipile is fully GDPR compliant. We act as a Data Processor, and all customer data is hosted exclusively within the European Union (France). We provide a Data Processing Agreement (DPA) upon request. There are no data transfers outside the EU.
We apply the principle of least privilege across all systems:
Multi-factor authentication (MFA) is mandatory for all internal tools
Production access is limited to a small number of authorized employees
Immediate access revocation upon employee departure or role change
All access is logged and auditable
Yes, we maintain a rigorous security testing program:
Penetration tests: Performed annually by independent third-party security firms
Security scans: Regular internal and external vulnerability scans
Continuous monitoring: Active security monitoring and supervision of metrics and logs
Code reviews: Systematic review before any deployment with protected branches
Unipile is a 100% remote company with no physical offices or on-premise servers. All infrastructure is hosted in secure Scaleway datacenters in France, where physical security is fully managed by Scaleway with enterprise-grade controls including 24/7 surveillance, biometric access, and redundant systems.
Yes, we provide full transparency on our security practices. The following documents are available upon request:
SOC 2 Type II Report – Full audit report
Data Processing Agreement (DPA) – GDPR compliance document
Security Whitepaper – Overview of our security architecture
Penetration Test Summary – Results from third-party security assessments
Use the form above to request any of these documents.
Still have security questions? Our team is here to help.