LEGAL · SECURITY

Security you can audit

Universal AI holds your whole company's data, so security is the product — not a checkbox. Here's how we protect it.

Isolation & encryption

Workspace isolation

Every query is scoped to your tenant at the data-access layer, so one customer's request cannot reach another's rows.

Encryption in transit

TLS 1.3 on every connection.

Encryption at rest

Uploaded files are stored with AES-256 server-side encryption. The database runs on managed Postgres with encrypted volumes.

No training on your data

Your workspace data is never used to train AI models or pooled across customers.

Access & accountability

Draft-first AI

No AI write reaches a customer without human approval, unless you grant scoped autonomy per agent.

Immutable audit log

Every action — human or AI — is recorded with who, what, and when, hash-chained so a tampered entry breaks the chain.

Roles & permissions

Granular RBAC; sensitive fields (like compensation) are masked unless a role explicitly allows them.

Multi-factor auth

TOTP two-factor with recovery codes, and trusted-device remembering.

Privacy requests

Submit a GDPR access or erasure request and we process it within the 30-day statutory window, tracked in-app with a visible clock. A Data Processing Addendum is available — see the DPA.

On the roadmap

Not built yet, and we will not pretend otherwise: SOC 2 attestation, HIPAA/BAA support, EU and US data residency, SAML single sign-on, and one-click self-serve data export. We would rather tell you what we do today than sell you a badge. If any of these gate a purchase for you, email security@universalai.com and we will give you a straight answer on timing.

Report a vulnerability

We welcome responsible disclosure. Email security@universalai.com with details and we'll respond promptly.