00Security

Customer data,
audit-friendly by default.

What we encrypt, who can access it, which vendors we use, and how we respond when something goes wrong. No marketing-asterisk.

SOC 2 Type II in progress · DPA available · sub-processors public
01Controls

Six controls we always have on.

No "best efforts." These run in production every day, are tested quarterly, and are documented in the evidence pack we ship under NDA.

01Control
Encryption

TLS 1.2+ in transit. AES-256 at rest. Customer secrets stored in Azure Key Vault with HSM-backed keys.

02Control
Access control

SSO + MFA required for all production systems. Role-based, least-privilege defaults. Access reviewed quarterly.

03Control
Audit logging

Every data-access event logged with actor, action, resource, timestamp. 90-day minimum retention; longer on enterprise plans.

04Control
Network

Private VPCs with no public ingress to data-plane services. Bastion-only SSH, broker-only DB access.

05Control
Backups

Encrypted, region-redundant, point-in-time recovery to 7 days. Tested quarterly via restore drills.

06Control
Pen testing

Independent third-party penetration test annually. Findings + remediation summaries available under NDA.

02Sub-processors

The vendor list. Fully public.

Customers are notified of new sub-processors 30 days in advance and may object. The current authoritative list is below.

Vendor
Purpose
Region
Azure
Compute, storage, key management
East US 2 / West Europe
Vercel
Web frontend hosting
Global edge
Supabase
Application database, auth
US-East / EU-West
Anthropic
LLM inference (default)
US
OpenAI
LLM inference (alt.)
US
Stripe
Payment processing
Global
Postmark
Transactional email
US
Sentry
Error monitoring
US / EU
03Compliance

Where we stand on the standards.

Honest about what we have, what we're working on, and what we don't support. No "compliance theater".

SOC 2 Type IIIn progress

Audit underway · Q3 2026 target

GDPR / UK GDPRCompliant

DPA + SCCs available

CCPA / CPRACompliant

Privacy rights honored within 30d

HIPAANot certified

PHI not supported on standard plans

ISO 27001Roadmap

Targeted post-SOC 2

PCI DSSStripe-scoped

No card data handled directly

Incident reporting

Suspect a vulnerability? Email security@unioneleven.ai — encrypted via PGP key on request. We acknowledge inside 24 hours.

Outcomes > output

Stop publishing.
Start compounding.

See the system on your own data. Bring a campaign or a quarter of CRM — we'll show you the brief, the assets, the test plan, and what the loop would ship in week one in 30 minutes.

30 min · with your data · no slideware
0
content channels per cycle
0D
lead scoring · fit · engagement · intent
0
live data adapters · GA4 · GSC · Firecrawl · Mailgun · LinkedIn
Daily
crew run cadence