Security

Security at UnisPath.

Counseling teams trust us with sensitive student information — transcripts, identity documents, application history. We treat that trust as our most important product feature.

Encryption in transit and at rest

All traffic is served over HTTPS via Google's managed load balancer. Application data, uploaded documents, database backups, and API credentials are encrypted at rest with Google-managed keys on Cloud SQL, Cloud Storage, and Secret Manager.

Role-based access control

Three user roles — student, organization member, and platform admin — see only what their role permits. Within an organization, members are designated as admins with full access; counselors are admins assigned to specific students. Role checks run server-side on every authenticated request.

Tenant isolation

Every student, application, document, and message record carries an organization_id. Server-side queries filter by the caller's organization before returning data, so one organization can't see another's records.

Audit logging

Infrastructure access, IAM changes, and admin operations are recorded by Google Cloud Audit Logs. Application status transitions and CRM ownership changes carry actor and timestamp metadata in the database.

Incident response

If we detect or are notified of a security incident affecting customer data, we will notify affected organizations without undue delay and follow up with a written post-incident summary.

Backups and recovery

Cloud SQL runs automated backups with point-in-time recovery enabled. Cloud Storage retains object versions so accidental deletions can be recovered.

Reporting a vulnerability

If you believe you've found a security issue, please contact us responsibly. We will acknowledge your report within 48 hours.

Contact security