Unico supports customers, partners, auditors and regulators across more than 21 countries. This Trust Center gives you visibility into the certifications, independent audits, governance structure and privacy program behind every Unico product.
Unico is a global identity network operating across Brazil, Mexico and the United States. Our governance, risk and compliance program is structured around internationally recognized frameworks — ISO/IEC 27001, 27701 and 42001 certifications, SOC 2 audits and independent laboratory testing — so that customers, auditors and regulators can verify our practices rather than take them on faith.
This portal is maintained by Unico's Governance, Risk & Compliance (GRC) team, and is updated as new certifications, audits and reports become available.
Need our SOC 2 report, ISO certificates or a security questionnaire completed?
compliance.unico@unico.ioQuestions about how we handle your personal data. Learn more about our governance structure, compliance with global privacy laws and the practices of our Privacy Program.
Privacy CenterFound a security issue? Report it responsibly through our HackerOne program.
hackerone.com/unico_idtechFull certificates and audit reports are available under NDA — request them below.
Information Security Management System (ISMS).
Privacy Information Management System (PIMS), extending 27001.
AI Management System — responsible governance of AI models.
ISO/IEC 30107-3 PAD compliant.
ISO/IEC 30107-3 highest tier.
PAD ★ tested 2025.
PAD ★★ tested 2025.
CEN/TS 18099 injection attack tested.
U.S. Department of Commerce.
Security & Availability controls, audited by KPMG.
Signatory committed to the Ten Principles on human rights, labor, environment and anti-corruption.
Member of the World Economic Forum community.
Certified carbon emissions offset — Seal ID 10025700.
Every control area below is mapped to ISO/IEC 27001:2022 Annex A and to SOC 2 Trust Services Criteria, owned by a designated area, and independently tested every year as part of our audit cycle.
All corporate and product access is centralized through a Cloud Directory IdP, integrating Single Sign-On (SSO) and Mobile Device Management (MDM).
MFA is required to access both the corporate environment and product environments, alongside a high-complexity password policy.
Access is granted by role after manager approval; an annual access-review process certifies that permissions remain compatible with current roles.
Access for terminated employees is automatically revoked across systems integrated with the corporate IdP as soon as offboarding is approved.
All data in transit is protected with TLS 1.2 or higher.
Data at rest is encrypted using native Google Cloud encryption with AES-256 keys, with automated certificate rotation and deployment.
IDCloud and IDPay run entirely on GCP using microservices and managed services in a multi-zonal architecture, with no self-managed data centers.
Workloads run across the us-east1 and us-central1 regions, each spanning 3+ physical data centers, backed by Google's 99.99% uptime SLA.
A Zero Trust approach and Web Application Firewall protect the perimeter against external attacks, with continuous threat monitoring.
Kubernetes Horizontal Pod Autoscaler and Cluster Autoscaler maintain capacity automatically; environments (dev/staging/prod) are securely isolated from each other.
A documented Secure Development Policy governs coding standards, code review and static/dynamic analysis before release.
Unico maintains a formal Bug Bounty Policy and performs regular internal and external penetration tests against infrastructure and applications.
Vulnerabilities are monitored constantly; identified issues automatically open a remediation ticket.
SIEM, EDR and DLP tools continuously monitor endpoints and the network, using AI/ML to detect and respond to suspicious behavior in real time.
A documented Security & Privacy Incident Response Policy defines containment, eradication and post-incident review, with root-cause analysis.
Annual simulated-incident exercises involving every relevant area validate the maturity and effectiveness of response plans.
Backups, snapshots and versioning run on Google Cloud Platform, protected by the same physical and logical security controls as production.
Disaster-recovery plans for IDCloud and IDPay are tested annually through planned and simulated exercises.
Dedicated reliability indicators track availability, incident classification and treatment across every product.
Anchored in global controls such as NIST, ISO/IEC 27701 and ISO/IEC 27001, Unico's Privacy Program is run by a multidisciplinary team that stays attentive to all applicable data protection laws. The maturity of our operation rests on 5 core pillars: solid Governance, Third-Party Risk Management, rigorous Security Incident Response protocols, a structured flow for Handling Data Subject Rights, and the continuous application of Privacy by Design and Risk Management in the design and development of every new product or feature.
Unico rigorously tracks privacy and data protection legislation globally, continuously evolving to stay ahead of regulatory updates and new market requirements.
PII masking in non-production environments, hiding personal data from engineers without authorized access.
Defined data retention and disposal policy, with secure deletion after the applicable retention period.
Encryption in transit (TLS 1.2+) and at rest (AES-256) for all personal data, including international transfers to contracted cloud providers.
Program maturity is measured against the NIST Privacy Framework and calculated from OKRs tracked across multiple areas of the organization.
The Data Protection Officer (DPO) operates at group level across all Unico companies, ensuring compliance with applicable global privacy laws and regulations. The DPO is the direct, official channel of communication between the company, data subjects and the competent data protection authorities in each jurisdiction where we operate.
privacy@unico.ioPersonal data may be transferred to and stored in Google's cloud in the United States in fully encrypted form. This transfer occurs solely to enable the delivery of our services and is supported by applicable Data Processing Agreements (DPAs) and Standard Contractual Clauses (SCCs), ensuring full compliance with the requirements of applicable data protection laws.
The pillars that sustain the maturity of our privacy operation.
Purpose: keeping the supply chain secure. We continuously assess and monitor vendors and partners so they handle data with the same rigor and compliance your company requires, closing off external vulnerabilities.
Purpose: preventive, built-in protection. We embed privacy into the DNA of every project, so that any new product, system or workflow is born with the highest standards of security and compliance — without slowing development down.
Purpose: order, culture and accountability. We set clear guidelines and policies across the organization so everyone understands their role in protecting data, making compliance a daily, auditable practice rather than just a document.
Purpose: trust and legal responsiveness. We run standardized, secure processes to respond quickly to user rights — such as access, correction or deletion of data — improving the customer experience and avoiding regulatory penalties.
Purpose: resilience and damage containment. We maintain a coordinated digital first-response plan. In the event of an incident, your company has clear processes to detect, contain and investigate the threat immediately, protecting brand reputation.
Purpose: innovation with responsibility. We implement legal and ethical safeguards so that the development and use of AI systems is transparent, safe and fully aligned with regulations, eliminating the risk of bias or violations.
Unico's normative documents are owned across Compliance, Privacy, Tech, Risk & Internal Controls and Operations, and are consolidated below for visibility.
| Policy | Owning area | Review cycle |
|---|---|---|
| Information Security Policy | Tech | Reviewed annually |
| Secure Development Policy | Tech | Reviewed annually |
| Identity & Access Management Policy | Tech | Reviewed annually |
| Vulnerability Management Policy | Tech | Reviewed annually |
| Information Classification Policy | Tech | Reviewed annually |
| Acceptable Use of Information Assets Policy | Tech | Reviewed annually |
| Firewall Governance Policy | Tech | Reviewed annually |
| Information Security & Privacy Incident Response Policy | Tech | Reviewed annually |
| Disaster Recovery & Contingency Plan for Information Assets and Technology Services | Tech | Reviewed annually |
| Threat Intelligence Policy | Tech | Reviewed annually |
| Patch & Software Update Management Policy | Tech | Reviewed annually |
| Information Security Event Monitoring Policy | Tech | Reviewed annually |
| IT Asset Lifecycle Management Policy | Tech | Reviewed annually |
| Backup & Restore Policy for Information Assets | Tech | Reviewed annually |
| Encryption Standard Policy | Tech | Reviewed annually |
| Change Management Policy | Tech | Reviewed annually |
| Equipment Donation Policy | Tech | Reviewed annually |
| Risk Management Policy | Risks & Internal Controls | Reviewed annually |
| Data Retention & Disposal Policy | Privacy | Reviewed annually |
| Internal Privacy Policy | Privacy | Reviewed annually |
| Code of Ethics & Conduct | Compliance | Reviewed annually |
Policies are reviewed annually or whenever a material change occurs, approved by senior leadership and published to Unico's internal policy repository, accessible to all employees. Current version numbers and last-review dates are available on request from our Compliance team.
Unico was created to simplify how businesses connect people to products and services — in a simple, reliable and secure way — while giving individuals back control over their data.
We value ethics, good conduct, diversity, respect and, above all, transparency and trust in every relationship — with employees, customers and business partners alike.
Available to any employee, customer or business partner who wishes to report a situation that contravenes Unico's commitments and policies.
Report via Ethics Channel →For anyone who has a question, wants clarification on our policies, or would like to share suggestions — no misconduct report required.
Access the Listening Channel →Unico runs on Google Cloud Platform across multiple availability zones and regions, giving customers in every market the same resilience, redundancy and compliance posture.
Global headquarters
Engineering hub
LatAm operations
North America office
Services run across us-east1 and us-central1, each spanning 3+ physical data centers, with a 99.99% provider SLA.
Our privacy program is aligned with internationally recognized data-protection frameworks, applied consistently across every market where we operate.
Annual disaster-recovery tests and table-top exercises across IDCloud and IDPay platforms.
Unico's IDCloud and IDPay platforms run entirely on Google Cloud Platform (GCP).
Yes. Unico holds a SOC 2 Type 2 report covering the Security and Availability Trust Services Criteria, audited by KPMG Assurance Services Ltda. for the period of January 1 to September 30, 2025. The full report is available under NDA — use the request form below.
Data in transit is protected with TLS 1.2 or higher. Data at rest is encrypted with native Google Cloud encryption using AES-256 keys, with automated key rotation and certificate deployment.
ISO/IEC 27001 (ISMS), ISO/IEC 27701 (PIMS), and ISO/IEC 42001 (AI Management System), a SOC 2 Type 2 report, and independent lab testing to ISO/IEC 30107-3 (Presentation Attack Detection, Levels 1 & 2) performed by ISO/IEC 17025-accredited laboratories. Unico is also a signatory of the UN Global Compact and a member of the World Economic Forum community.
Yes. In the context of providing our B2B services, personal data may be transferred to and stored in the Google cloud in the United States, in fully encrypted form. The transfer is backed by applicable Data Processing Agreements (DPAs) and Standard Contractual Clauses (SCCs), with data remaining encrypted throughout the process and in compliance with applicable data protection laws.
Unico's liveness and anti-spoofing engines are independently evaluated by accredited laboratories — including BixeLab (NVLAP Lab Code 600301-0, ISO/IEC 17025-accredited) and iBeta — against ISO/IEC 30107-3 (Presentation Attack Detection, Levels 1 & 2) and injection-attack scenarios aligned with CEN/TS 18099.
Use the "Request access" form at the bottom of this page. Our Compliance team reviews every request and shares documentation under NDA with verified business contacts, typically within 2 business days.
SOC 2 report, ISO certificates, penetration test summaries and completed security questionnaires are shared under NDA with verified business contacts.