Security transparency without operational exposure.
UnoLock publishes a sanitized public security package. Full SOC 2 evidence, control mappings, auditor materials, operational screenshots, internal procedures, and detailed infrastructure records are kept under controlled access.
SOC 2 audit preparation has been completed; an independent audit is pending. UnoLock maintains a SOC 2-aligned security control framework and has prepared evidence for independent audit review. Full audit materials and control evidence are available only to qualified auditors, enterprise customers, or partners under appropriate confidentiality terms. UnoLock does not publicly claim SOC 2 certification unless and until an independent audit report has been issued.
Public Trust Package
- Security posture and architecture summary.
- Zero-knowledge and no-plaintext-access explanation.
- Encryption, deletion, privacy, and retention summaries.
- Incident response, vulnerability disclosure, and continuity principles.
Controlled Access
- SOC 2 readiness summaries.
- Security questionnaire responses.
- Sanitized architecture diagrams.
- Executive summaries for qualified customer diligence.
Private Evidence Room
- Control mappings, screenshots, and audit evidence.
- Access reviews, logs, tickets, and policy attestations.
- Internal procedures, vendor evidence, and operating records.
- Available only to authorized auditors or tightly controlled reviewers.
What UnoLock can access
UnoLock can operate the service, process payments through payment providers, serve application code, store encrypted objects, and maintain limited server control records needed to run the platform. Those records are operational fields, not plaintext user-authored metadata.
What UnoLock cannot access
UnoLock is designed so plaintext Safe contents, private keys, recovery material, decrypted files, and user-provided metadata such as names, labels, descriptions, Space names, and message metadata remain on the user's trusted client. We do not publish operational details that would weaken that boundary.
If TechSologic is compromised
The system is designed to limit blast radius through client-side encryption and separation of responsibilities. Service compromise should not grant readable access to Safe contents.