Security at UTICOS
UTICOS LLC · Last updated: [DATE OF PUBLICATION]
DRAFT: every statement must match the live system before publication.
Your brand, your products and your plans are business-sensitive. This page explains, in plain words, how we protect them. It describes what we do today; we don't claim any certification we don't hold.
Data in transit and at rest
- All traffic between your browser, our website and our servers is encrypted with TLS (HTTPS). Plain HTTP is not accepted, and the site sends HSTS.
- Your data is stored with established cloud providers:
- Neon for the database;
- Cloudflare R2 for photos and media;
- Fly.io for the application servers.
- These providers encrypt data at rest on their infrastructure. [CONFIRM per provider.]
- Media files are delivered through time-limited signed links, not public addresses.
Accounts and access
- Passwords are stored only as one-way hashes (bcrypt). We cannot see your password.
- Failed sign-ins are limited per IP address and per email: 5 attempts in 15 minutes. After that, sign-in pauses and tells you when you can try again.
- Each business's data is separated by account. Every request is checked against the account it belongs to, and automated tests guard these checks.
- Team access is limited by role. The account owner controls who is invited and can remove access at any time.
Inside UTICOS
- Access to production systems is limited to the people who need it, and secured with strong authentication.
- Secrets and API keys are kept in the hosting provider's secret store, never in our code.
- Every change to the Service passes an automated test suite of more than 8,000 tests before release. Each release is verified on production after it is deployed.
- Every paid call to an AI provider passes a spending gate. The gate checks who authorised it and enforces cost limits, and it refuses before the call is made.
AI providers
- We send AI providers only what a task needs: for example, a product photo and a brief to generate a reel. They are listed in our Privacy Policy.
- We do not use your content to train our own models. [CONFIRM: each provider's API terms state that API inputs are not used for training by default.]
Monitoring and backups
- Errors are reported to a monitoring service, so problems are found and fixed quickly.
- The database provider keeps automated backups that allow recovery to an earlier point in time. [CONFIRM: retention window.]
If something goes wrong
If we learn of a security incident that affects your data, we will:
- contain it;
- investigate it;
- notify affected customers and the competent authority as the law requires; and
- explain what happened and what we changed.
Reporting a vulnerability
If you believe you have found a security issue, please email technical@uticos.com with the details and how to reproduce it. Give us reasonable time to fix it before you disclose it publicly, and do not access other customers' data, disrupt the Service or use automated scanners against production. We will acknowledge your report and keep you updated.
Contact
Security questions: technical@uticos.com