Security
Last updated June 11, 2026
Unifix holds the records businesses rely on to run their work — and the personal details of the clients they serve. Protecting that data is part of the product, not an afterthought. Here's how we approach it.
Encryption
All traffic to and from Unifix is encrypted in transit with TLS. Sensitive fields and personal information are encrypted at rest, and database backups are encrypted. Card details never touch our servers (see Payments below).
Infrastructure
Unifix runs on established cloud infrastructure — including PlanetScale, Amazon Web Services, Hetzner, and Cloudflare — whose data centers provide physical security, power and network redundancy, and maintain independent security certifications such as SOC 2 and ISO 27001. We keep our systems patched and rely on managed, regularly-tested backups.
Tenant isolation
Unifix is multi-tenant: every customer is a separate account, and all data is partitioned by account. The application scopes every request to the signed-in user's account, so a user can only ever reach data that belongs to their own account — there's no path through the product to another customer's data, and each session is bound to a single account. We use shared, logically-isolated infrastructure rather than a separate database per customer, which is the standard model for software of this kind.
Access to your data
Internally, access to customer data follows the principle of least privilege: our staff access the data in your account only when you ask us to for support, when it's needed to diagnose or fix a problem, when it's needed to keep the Service secure, or when the law compels us.
Payments
Billing is handled by Stripe, a PCI-DSS Level 1 certified payment provider. We never see or store full card numbers — Stripe processes payment details directly.
Monitoring and resilience
We monitor the Service with error tracking and logging so we can detect and respond to problems quickly. If a security incident ever affects your data, we'll notify affected customers without undue delay, as set out in our Data Processing Addendum.
Subprocessors
We keep the list of vendors we rely on — and what protects the data they handle — current in our Privacy Policy.
Reporting a vulnerability
If you believe you've found a security vulnerability, we want to hear about it. Email security@unifix.io with the details. We investigate every report, and we won't pursue or support legal action against researchers who report in good faith and avoid privacy violations, data destruction, or service disruption while testing.
Questions
Security or compliance questions — including help with a vendor security review — are welcome at security@unifix.io.