Skip to main content

Security is built into Unestra, not bolted on

How we protect your organization's data, members, and payments.

Encrypted connections

All traffic to Unestra Cloud and the member portal is encrypted in transit over HTTPS/TLS.

Secure authentication

Passwords are hashed, never stored in plain text. Sessions use secure, host-only cookies.

Multi-factor authentication

Administrators can enable MFA on their accounts for an additional layer of login protection.

Role-based access control

Every user is assigned a role that defines exactly what they can see and do — least-privilege by default.

Tenant separation

Every organization's data is logically isolated from every other organization on the platform.

Audit logging

Sensitive actions are recorded with a timestamp and actor, so administrators can review who did what.

Secure payment processing

Payments are processed through Stripe. Unestra never stores full card numbers on its own servers.

Authenticated email delivery

Transactional email is sent through domain-authenticated infrastructure (SPF, DKIM, and DMARC).

Backups

Production data is backed up regularly by our managed database provider.

Access controls

Production infrastructure access is limited to the individuals who need it to operate the platform.

What we don't claim

We believe in being precise about our security posture. Unestra does not currently hold SOC 2, HIPAA, PCI, or ISO certifications, and we do not claim end-to-end encryption. If your organization requires a specific compliance certification, please contact us to discuss your requirements before subscribing.

Responsible disclosure

If you believe you've found a security vulnerability in Unestra, please report it to us directly rather than disclosing it publicly. We'll investigate every report.

security@getunestra.com