Security transparency without operational exposure.

UnoLock publishes a sanitized public security package. Full SOC 2 evidence, control mappings, auditor materials, operational screenshots, internal procedures, and detailed infrastructure records are kept under controlled access.

SOC 2 audit preparation has been completed; an independent audit is pending. UnoLock maintains a SOC 2-aligned security control framework and has prepared evidence for independent audit review. Full audit materials and control evidence are available only to qualified auditors, enterprise customers, or partners under appropriate confidentiality terms. UnoLock does not publicly claim SOC 2 certification unless and until an independent audit report has been issued.

Public Trust Package

  • Security posture and architecture summary.
  • Zero-knowledge and no-plaintext-access explanation.
  • Encryption, deletion, privacy, and retention summaries.
  • Incident response, vulnerability disclosure, and continuity principles.

Controlled Access

  • SOC 2 readiness summaries.
  • Security questionnaire responses.
  • Sanitized architecture diagrams.
  • Executive summaries for qualified customer diligence.

Private Evidence Room

  • Control mappings, screenshots, and audit evidence.
  • Access reviews, logs, tickets, and policy attestations.
  • Internal procedures, vendor evidence, and operating records.
  • Available only to authorized auditors or tightly controlled reviewers.

What UnoLock can access

UnoLock can operate the service, process payments through payment providers, serve application code, store encrypted objects, and maintain limited server control records needed to run the platform. Those records are operational fields, not plaintext user-authored metadata.

What UnoLock cannot access

UnoLock is designed so plaintext Safe contents, private keys, recovery material, decrypted files, and user-provided metadata such as names, labels, descriptions, Space names, and message metadata remain on the user's trusted client. We do not publish operational details that would weaken that boundary.

If TechSologic is compromised

The system is designed to limit blast radius through client-side encryption and separation of responsibilities. Service compromise should not grant readable access to Safe contents.

Security Commitments

Controls Documented controls cover access management, change management, incident response, encryption, data handling, infrastructure security, vendor management, vulnerability management, and business continuity.
Threat Model UnoLock treats hostile devices, credential theft, coercion, infrastructure compromise, and supply-chain pressure as first-class risks. Public materials explain the model without publishing attacker playbooks.
Encryption Safe contents are encrypted before leaving the client. Public documentation explains the boundary at a high level; implementation evidence and detailed operational records stay controlled.
Data Residency UnoLock supports region-aware storage options where available by plan and configuration. Specific customer residency commitments are handled contractually.
Deletion UnoLock publishes retention and deletion commitments while keeping exact internal execution details, verification artifacts, and operational procedures private.
Vulnerabilities Security reports should be sent through the channels listed on the support, vulnerability policy, and bug bounty pages. Confirmed issues are triaged and handled according to severity and user impact.