Dark icon of a graph with an upward trending line and three data points connected by segments.
Trust Center

Verifiable trust, governed and audited at every layer

Unico supports customers, partners, auditors and regulators across more than 21 countries. This Trust Center gives you visibility into the certifications, independent audits, governance structure and privacy program behind every Unico product.

5
international certifications & independent audits
1.2B+
authentications processed last year
21+
countries with active operations
99.99%
cloud infrastructure uptime SLA
Dark icon of a graph with an upward trending line and three data points connected by segments.
Trust at Unico

Trust, backed by governance and independent audits

Unico is a global identity network operating across Brazil, Mexico and the United States. Our governance, risk and compliance program is structured around internationally recognized frameworks — ISO/IEC 27001, 27701 and 42001 certifications, SOC 2 audits and independent laboratory testing — so that customers, auditors and regulators can verify our practices rather than take them on faith.

This portal is maintained by Unico's Governance, Risk & Compliance (GRC) team, and is updated as new certifications, audits and reports become available.

Dark icon of a graph with an upward trending line and three data points connected by segments.
UN Global Compact signatory
Dark icon of a graph with an upward trending line and three data points connected by segments.
World Economic Forum community member
Enterprise & compliance requests

Need our SOC 2 report, ISO certificates or a security questionnaire completed?

compliance.unico@unico.io
Privacy & data protection

Questions about how we handle your personal data. Learn more about our governance structure, compliance with global privacy laws and the practices of our Privacy Program.

Privacy Center
Report a vulnerability

Found a security issue? Report it responsibly through our HackerOne program.

hackerone.com/unico_idtech
Dark icon of a graph with an upward trending line and three data points connected by segments.
Certifications & audits

The gold standard of identity, audited globally

Full certificates and audit reports are available under NDA — request them below.

ISO/IEC 27001

Information Security Management System (ISMS).

Certified
ISO/IEC 27001 is the leading international standard for Information Security Management Systems. Unico's ISMS covers access control, cryptography, operations security, incident management and supplier relationships, and is independently audited on an annual surveillance cycle.
ISO/IEC 27001:2022
Unico IDCloud & IDPay platforms
ISO/IEC 27701

Privacy Information Management System (PIMS), extending 27001.

Certified
ISO/IEC 27701 expands Unico's ISMS (ISO 27001) into a complete Privacy Information Management System (PIMS). This evolution formalizes our personal-data processing practices — whether acting as controller or processor — and consolidates the foundation of our global compliance program.
ISO/IEC 27701:2019
Personal data processing, IDCloud & IDPay
ISO/IEC 42001

AI Management System — responsible governance of AI models.

Certified
ISO/IEC 42001 is the first international standard for Artificial Intelligence Management Systems. It governs how Unico designs, trains, monitors and audits the AI and machine-learning models behind our biometric and fraud-detection engines, with a focus on accountability, transparency and risk management.
ISO/IEC 42001:2023
AI / ML models — biometrics & fraud detection
iBeta – Level 1

ISO/IEC 30107-3 PAD compliant.

PAD compliant
Unico's liveness technology is independently tested by iBeta, an ISO/IEC 17025-accredited laboratory, and confirmed compliant with ISO/IEC 30107-3 Presentation Attack Detection (PAD) Level 1. This certification is also published on Unico's institutional site (unico.io).
ISO/IEC 30107-3 — PAD Level 1
Liveness / anti-spoofing engines
iBeta – Level 2

ISO/IEC 30107-3 highest tier.

PAD compliant
Unico's liveness technology is independently tested by iBeta and confirmed compliant with ISO/IEC 30107-3 Presentation Attack Detection (PAD) Level 2, the standard's highest sophistication tier. This certification is also published on Unico's institutional site (unico.io).
ISO/IEC 30107-3 — PAD Level 2
Liveness / anti-spoofing engines
BixeLab – Level 1

PAD ★ tested 2025.

Tested 2025
Unico's liveness technology is independently evaluated by BixeLab (NVLAP Lab Code 600301-0, ISO/IEC 17025-accredited) against Presentation Attack Detection Level 1 (★) requirements. This certification is also published on Unico's institutional site (unico.io).
BixeLab PAD ★ (2025)
Liveness / anti-spoofing engines
BixeLab – Level 2

PAD ★★ tested 2025.

Tested 2025
Unico's liveness technology is independently evaluated by BixeLab against Presentation Attack Detection Level 2 (★★) requirements, the highest PAD sophistication level tested by BixeLab. This certification is also published on Unico's institutional site (unico.io).
BixeLab PAD ★★ (2025)
Liveness / anti-spoofing engines
BixeLab – IAD

CEN/TS 18099 injection attack tested.

Tested 2025
Unico's liveness technology is independently evaluated by BixeLab for Injection Attack Detection (IAD), aligned with the CEN/TS 18099 technical specification. This certification is also published on Unico's institutional site (unico.io).
CEN/TS 18099 (2025)
Liveness / anti-spoofing engines
Tested by NIST

U.S. Department of Commerce.

Tested
Unico's face recognition technology has been evaluated by the National Institute of Standards and Technology (NIST), part of the U.S. Department of Commerce. This certification is also published on Unico's institutional site (unico.io).
NIST FRVT
Face recognition engines
SOC 2 Type 2

Security & Availability controls, audited by KPMG.

Audited
Unico's IDCloud and IDPay platforms hold a SOC 2 Type 2 report covering the Security and Availability Trust Services Criteria, independently audited by KPMG Assurance Services Ltda. for the period of January 1 to September 30, 2025, with an unqualified opinion on the design and operating effectiveness of controls.
AICPA TSC 2017 (Security & Availability)
Unico IDCloud & IDPay
UN Global Compact

Signatory committed to the Ten Principles on human rights, labor, environment and anti-corruption.

Signatory
Unico is a signatory of the United Nations Global Compact, committing to align its operations and strategy with the Ten Principles on human rights, labor, environment and anti-corruption, and to report annually on progress.
UN Global Compact
Unico global operations
World Economic Forum

Member of the World Economic Forum community.

Member
Unico participates in the World Economic Forum community, contributing to and staying aligned with global dialogue on digital identity, trust and the responsible use of AI in financial and public services.
World Economic Forum
Unico global engagement
Carbon Free Brasil

Certified carbon emissions offset — Seal ID 10025700.

Certified
Unico holds the Carbon Free Brasil seal (ID 10025700), certifying that our calculated carbon emissions are measured and offset in accordance with the program's methodology. The certificate is independently verifiable at carbonfreebrasil.com.
Carbon Free Brasil — ID 10025700
Unico operations (Brazil)
Dark icon of a graph with an upward trending line and three data points connected by segments.
Governance & controls

Controls governed, documented and audited across every layer

Every control area below is mapped to ISO/IEC 27001:2022 Annex A and to SOC 2 Trust Services Criteria, owned by a designated area, and independently tested every year as part of our audit cycle.

Access Control
Data Security
Infrastructure
Application Security
Monitoring & Incident Response
Business Continuity
Centralized identity provider

All corporate and product access is centralized through a Cloud Directory IdP, integrating Single Sign-On (SSO) and Mobile Device Management (MDM).

Multi-factor authentication

MFA is required to access both the corporate environment and product environments, alongside a high-complexity password policy.

Role-based access & annual review

Access is granted by role after manager approval; an annual access-review process certifies that permissions remain compatible with current roles.

Automated deprovisioning

Access for terminated employees is automatically revoked across systems integrated with the corporate IdP as soon as offboarding is approved.

Encryption in transit

All data in transit is protected with TLS 1.2 or higher.

Encryption at rest

Data at rest is encrypted using native Google Cloud encryption with AES-256 keys, with automated certificate rotation and deployment.

Google Cloud Platform, cloud-native

IDCloud and IDPay run entirely on GCP using microservices and managed services in a multi-zonal architecture, with no self-managed data centers.

Multi-region redundancy

Workloads run across the us-east1 and us-central1 regions, each spanning 3+ physical data centers, backed by Google's 99.99% uptime SLA.

Zero Trust & WAF

A Zero Trust approach and Web Application Firewall protect the perimeter against external attacks, with continuous threat monitoring.

Auto-scaling & isolation

Kubernetes Horizontal Pod Autoscaler and Cluster Autoscaler maintain capacity automatically; environments (dev/staging/prod) are securely isolated from each other.

Secure development lifecycle

A documented Secure Development Policy governs coding standards, code review and static/dynamic analysis before release.

Bug bounty & penetration testing

Unico maintains a formal Bug Bounty Policy and performs regular internal and external penetration tests against infrastructure and applications.

Vulnerability management

Vulnerabilities are monitored constantly; identified issues automatically open a remediation ticket.

24/7 detection stack

SIEM, EDR and DLP tools continuously monitor endpoints and the network, using AI/ML to detect and respond to suspicious behavior in real time.

Formal incident response

A documented Security & Privacy Incident Response Policy defines containment, eradication and post-incident review, with root-cause analysis.

Table-top exercises

Annual simulated-incident exercises involving every relevant area validate the maturity and effectiveness of response plans.

Automated backups

Backups, snapshots and versioning run on Google Cloud Platform, protected by the same physical and logical security controls as production.

Annual DR testing

Disaster-recovery plans for IDCloud and IDPay are tested annually through planned and simulated exercises.

Reliability monitoring

Dedicated reliability indicators track availability, incident classification and treatment across every product.

Dark icon of a graph with an upward trending line and three data points connected by segments.
Privacy program

Privacy Program

Anchored in global controls such as NIST, ISO/IEC 27701 and ISO/IEC 27001, Unico's Privacy Program is run by a multidisciplinary team that stays attentive to all applicable data protection laws. The maturity of our operation rests on 5 core pillars: solid Governance, Third-Party Risk Management, rigorous Security Incident Response protocols, a structured flow for Handling Data Subject Rights, and the continuous application of Privacy by Design and Risk Management in the design and development of every new product or feature.

Unico rigorously tracks privacy and data protection legislation globally, continuously evolving to stay ahead of regulatory updates and new market requirements.

PII masking in non-production environments, hiding personal data from engineers without authorized access.

Defined data retention and disposal policy, with secure deletion after the applicable retention period.

Encryption in transit (TLS 1.2+) and at rest (AES-256) for all personal data, including international transfers to contracted cloud providers.

Program maturity is measured against the NIST Privacy Framework and calculated from OKRs tracked across multiple areas of the organization.

Data Protection Officer (DPO)

The Data Protection Officer (DPO) operates at group level across all Unico companies, ensuring compliance with applicable global privacy laws and regulations. The DPO is the direct, official channel of communication between the company, data subjects and the competent data protection authorities in each jurisdiction where we operate.

privacy@unico.io
International data transfers

Personal data may be transferred to and stored in Google's cloud in the United States in fully encrypted form. This transfer occurs solely to enable the delivery of our services and is supported by applicable Data Processing Agreements (DPAs) and Standard Contractual Clauses (SCCs), ensuring full compliance with the requirements of applicable data protection laws.

Unico Privacy Program

The pillars that sustain the maturity of our privacy operation.

Third-Party Risk Management (TPRM)
+

Purpose: keeping the supply chain secure. We continuously assess and monitor vendors and partners so they handle data with the same rigor and compliance your company requires, closing off external vulnerabilities.

Privacy by Design (PbD)
+

Purpose: preventive, built-in protection. We embed privacy into the DNA of every project, so that any new product, system or workflow is born with the highest standards of security and compliance — without slowing development down.

Governance
+

Purpose: order, culture and accountability. We set clear guidelines and policies across the organization so everyone understands their role in protecting data, making compliance a daily, auditable practice rather than just a document.

Data Subject Requests
+

Purpose: trust and legal responsiveness. We run standardized, secure processes to respond quickly to user rights — such as access, correction or deletion of data — improving the customer experience and avoiding regulatory penalties.

Data Breach Response
+

Purpose: resilience and damage containment. We maintain a coordinated digital first-response plan. In the event of an incident, your company has clear processes to detect, contain and investigate the threat immediately, protecting brand reputation.

Artificial Intelligence (AI) Governance
+

Purpose: innovation with responsibility. We implement legal and ethical safeguards so that the development and use of AI systems is transparent, safe and fully aligned with regulations, eliminating the risk of bias or violations.

Dark icon of a graph with an upward trending line and three data points connected by segments.
Policies & procedures

One policy framework, spanning security, privacy and compliance

Unico's normative documents are owned across Compliance, Privacy, Tech, Risk & Internal Controls and Operations, and are consolidated below for visibility.

PolicyOwning areaReview cycle
Information Security PolicyTechReviewed annually
Secure Development PolicyTechReviewed annually
Identity & Access Management PolicyTechReviewed annually
Vulnerability Management PolicyTechReviewed annually
Information Classification PolicyTechReviewed annually
Acceptable Use of Information Assets PolicyTechReviewed annually
Firewall Governance PolicyTechReviewed annually
Information Security & Privacy Incident Response PolicyTechReviewed annually
Disaster Recovery & Contingency Plan for Information Assets and Technology ServicesTechReviewed annually
Threat Intelligence PolicyTechReviewed annually
Patch & Software Update Management PolicyTechReviewed annually
Information Security Event Monitoring PolicyTechReviewed annually
IT Asset Lifecycle Management PolicyTechReviewed annually
Backup & Restore Policy for Information AssetsTechReviewed annually
Encryption Standard PolicyTechReviewed annually
Change Management PolicyTechReviewed annually
Equipment Donation PolicyTechReviewed annually
Risk Management PolicyRisks & Internal ControlsReviewed annually
Data Retention & Disposal PolicyPrivacyReviewed annually
Internal Privacy PolicyPrivacyReviewed annually
Code of Ethics & ConductComplianceReviewed annually

Policies are reviewed annually or whenever a material change occurs, approved by senior leadership and published to Unico's internal policy repository, accessible to all employees. Current version numbers and last-review dates are available on request from our Compliance team.

Dark icon of a graph with an upward trending line and three data points connected by segments.
Ethics & compliance

Being unique means doing the right thing

Unico was created to simplify how businesses connect people to products and services — in a simple, reliable and secure way — while giving individuals back control over their data.

We value ethics, good conduct, diversity, respect and, above all, transparency and trust in every relationship — with employees, customers and business partners alike.

Ethics Channel

Available to any employee, customer or business partner who wishes to report a situation that contravenes Unico's commitments and policies.

Report via Ethics Channel →
Listening Channel

For anyone who has a question, wants clarification on our policies, or would like to share suggestions — no misconduct report required.

Access the Listening Channel →
Dark icon of a graph with an upward trending line and three data points connected by segments.
Global operations

Built to serve regulated markets, everywhere

Unico runs on Google Cloud Platform across multiple availability zones and regions, giving customers in every market the same resilience, redundancy and compliance posture.

São Paulo, BR

Global headquarters

Londrina, BR

Engineering hub

Mexico City, MX

LatAm operations

Menlo Park, US

North America office

Multi-region resilience

Services run across us-east1 and us-central1, each spanning 3+ physical data centers, with a 99.99% provider SLA.

Regulatory alignment

Our privacy program is aligned with internationally recognized data-protection frameworks, applied consistently across every market where we operate.

Business continuity

Annual disaster-recovery tests and table-top exercises across IDCloud and IDPay platforms.

Dark icon of a graph with an upward trending line and three data points connected by segments.
Knowledge base

Frequently asked questions

Where is Unico's data hosted?
+

Unico's IDCloud and IDPay platforms run entirely on Google Cloud Platform (GCP).

Does Unico have a SOC 2 report?
+

Yes. Unico holds a SOC 2 Type 2 report covering the Security and Availability Trust Services Criteria, audited by KPMG Assurance Services Ltda. for the period of January 1 to September 30, 2025. The full report is available under NDA — use the request form below.

How is personal data encrypted?
+

Data in transit is protected with TLS 1.2 or higher. Data at rest is encrypted with native Google Cloud encryption using AES-256 keys, with automated key rotation and certificate deployment.

Which certifications does Unico hold?
+

ISO/IEC 27001 (ISMS), ISO/IEC 27701 (PIMS), and ISO/IEC 42001 (AI Management System), a SOC 2 Type 2 report, and independent lab testing to ISO/IEC 30107-3 (Presentation Attack Detection, Levels 1 & 2) performed by ISO/IEC 17025-accredited laboratories. Unico is also a signatory of the UN Global Compact and a member of the World Economic Forum community.

Does Unico transfer personal data internationally?
+

Yes. In the context of providing our B2B services, personal data may be transferred to and stored in the Google cloud in the United States, in fully encrypted form. The transfer is backed by applicable Data Processing Agreements (DPAs) and Standard Contractual Clauses (SCCs), with data remaining encrypted throughout the process and in compliance with applicable data protection laws.

How does Unico test its biometric / liveness technology?
+

Unico's liveness and anti-spoofing engines are independently evaluated by accredited laboratories — including BixeLab (NVLAP Lab Code 600301-0, ISO/IEC 17025-accredited) and iBeta — against ISO/IEC 30107-3 (Presentation Attack Detection, Levels 1 & 2) and injection-attack scenarios aligned with CEN/TS 18099.

How can I request the full SOC 2 report or ISO certificates?
+

Use the "Request access" form at the bottom of this page. Our Compliance team reviews every request and shares documentation under NDA with verified business contacts, typically within 2 business days.

Dark icon of a graph with an upward trending line and three data points connected by segments.
Get access

Request our full documentation

SOC 2 report, ISO certificates, penetration test summaries and completed security questionnaires are shared under NDA with verified business contacts.

By submitting, you agree to receive a response from Unico's Compliance team at the email provided. Your information is secure and will only be used to process your request.

Thank you. Our Compliance team reviews every request and will get back to you at the email you provided, typically within 2 business days. Documentation is shared under NDA with verified business contacts.

Oops! Something went wrong while submitting the form.