Base44 APP

Security Statement

How Unity protects its own systems and client data through security controls, operational practices, and continuous monitoring.

Unity's Security Posture

As a managed IT services provider serving healthcare organizations, Unity maintains rigorous security controls for our own infrastructure and operations. These same practices inform how we design and manage client environments.

This statement provides a public-facing summary of Unity's security approach. Detailed security documentation, including specific technical controls and audit evidence, is available to prospective and current clients under appropriate confidentiality agreements.

Key Security Controls

Access Management

Multi-factor authentication required for all Unity staff. Role-based access controls limit data access to only what's necessary for job functions. Regular access reviews verify appropriate permissions.

Security Monitoring

24/7 monitoring of our own infrastructure and client environments under management. Security event logging, analysis, and alerting for potential threats or policy violations.

Vulnerability Management

Systematic patch management for all Unity systems. Regular vulnerability scanning and prompt remediation. Security update testing before deployment to production.

Security Training

All Unity staff complete security awareness training covering phishing, social engineering, data protection, and incident reporting. Annual refresher training required.

Infrastructure Security

Unity's own IT infrastructure follows the same security-first principles we implement for clients:

  • Cloud-first architecture: Primary infrastructure hosted in Microsoft Azure with enterprise-grade security controls
  • Network segmentation: Separation of administrative, production, and client environments
  • Endpoint protection: All Unity devices run next-generation antivirus, endpoint detection and response, and disk encryption
  • Backup and recovery: Regular backups with documented recovery procedures and periodic restoration testing
  • Logging and monitoring: Centralized log collection and security event analysis

Access Control & Least Privilege

Unity operates on a least-privilege access model. Staff members receive only the minimum access necessary to perform their job responsibilities. Access to client systems is strictly controlled and logged.

Key access control practices:

  • Multi-factor authentication required for all Unity systems and client environments
  • Role-based access controls aligned with job functions
  • Regular access reviews (quarterly) to verify appropriate permissions
  • Immediate access revocation upon employment termination
  • Privileged access management for administrative accounts
  • All administrative actions logged for audit purposes

Client data is accessible only to Unity staff with legitimate business need (such as assigned technicians supporting that client). Access is logged and subject to audit.

Security Training & Awareness

Technology controls alone are insufficient. Unity maintains a security-aware culture through mandatory training and ongoing reinforcement:

  • All new employees complete security awareness training during onboarding
  • Annual refresher training covering current threats and best practices
  • Specific training for healthcare data handling and HIPAA requirements
  • Phishing simulation exercises to test and reinforce awareness
  • Clear incident reporting procedures and non-punitive reporting culture

Staff are trained to recognize and report security concerns, social engineering attempts, and potential policy violations without fear of reprisal.

Incident Response

Unity maintains documented incident response procedures covering detection, containment, investigation, recovery, and post-incident analysis. Security incidents are classified by severity with appropriate escalation paths.

Our incident response process integrates with client notification requirements, particularly for healthcare organizations with HIPAA breach notification obligations.

Report Security Concerns

If you discover a security vulnerability in Unity's systems or have concerns about our security practices, please report them promptly.

Security Contact: security@unitytn.com

We take security reports seriously and will respond to legitimate concerns within 1 business day.

Additional Security Information

This security statement provides a public overview of Unity's security approach. Organizations evaluating Unity for potential engagement can request:

  • Detailed security documentation
  • Evidence of specific security controls
  • Third-party security assessments or audit reports
  • Business Associate Agreement templates
  • Incident response procedures

These materials are provided under appropriate confidentiality agreements during the evaluation and onboarding process.

Questions About Our Security Practices?

We're happy to discuss our security controls and practices in detail.