Security
Security is built into Unestra, not bolted on
How we protect your organization's data, members, and payments.
Encrypted connections
All traffic to Unestra Cloud and the member portal is encrypted in transit over HTTPS/TLS.
Secure authentication
Passwords are hashed, never stored in plain text. Sessions use secure, host-only cookies.
Multi-factor authentication
Administrators can enable MFA on their accounts for an additional layer of login protection.
Role-based access control
Every user is assigned a role that defines exactly what they can see and do — least-privilege by default.
Tenant separation
Every organization's data is logically isolated from every other organization on the platform.
Audit logging
Sensitive actions are recorded with a timestamp and actor, so administrators can review who did what.
Secure payment processing
Payments are processed through Stripe. Unestra never stores full card numbers on its own servers.
Authenticated email delivery
Transactional email is sent through domain-authenticated infrastructure (SPF, DKIM, and DMARC).
Backups
Production data is backed up regularly by our managed database provider.
Access controls
Production infrastructure access is limited to the individuals who need it to operate the platform.
What we don't claim
We believe in being precise about our security posture. Unestra does not currently hold SOC 2, HIPAA, PCI, or ISO certifications, and we do not claim end-to-end encryption. If your organization requires a specific compliance certification, please contact us to discuss your requirements before subscribing.
Responsible disclosure
If you believe you've found a security vulnerability in Unestra, please report it to us directly rather than disclosing it publicly. We'll investigate every report.
security@getunestra.com