Independently verified standards help demonstrate that security controls are built into UnoPim.
Supports data protection & privacy practices
UnoPim's security posture is backed by recognized third-party frameworks that govern how we build, host, and support the platform — reviewed and renewed on a regular cycle rather than treated as a one-time badge.
Our information security management practices are aligned with ISO 27001, covering how we govern access, infrastructure, and product development end to end.
Engineering and organizational processes are assessed at CMMI Level 3 maturity, meaning development, testing, and release practices are defined, documented, and repeatable.
An independent SOC 2 Type II attestation provides assurance over controls within the scope defined by the SOC 2 report.
Our quality management system is certified to ISO 9001, reinforcing consistent, documented processes across support, delivery, and product operations.
UnoPim Cloud runs on hardened, monitored infrastructure with network isolation between customer environments — so your catalog data stays available, backed up, and out of reach of anyone but your team.
Uptime target for UnoPim Cloud environments
Infrastructure monitoring and alerting
Maximum patch window for critical severity issues
Each customer environment runs in its own isolated network, preventing lateral movement and containing potential threats.
Servers ship with a reduced attack surface — minimizing unnecessary services to reduce vulnerabilities.
Catalog data is backed up on a regular schedule, with restore procedures tested regularly to ensure data is recoverable.
Infrastructure and application logs are watched around the clock to detect anomalies across the application layer.
Data is encrypted in transit and at rest across every layer using AES-256 to protect sensitive product information.
Security-relevant events follow a defined escalation plan, ensuring swift investigation and communication.
ISO 27001, CMMI Level 3, SOC 2, and ISO 9001 are publicly verifiable at webkul.com/about-us/certification. The SOC 2 report and further compliance documentation can be shared with you or your clients on request — ask our team →. Our vulnerability disclosure policy, response times and supported-version table are public at github.com/unopim/unopim/security/policy.
UnoPim's security practices are owned by our engineering and compliance leadership and reviewed on a continuous basis rather than revisited once a year. Policies covering access control, secure development, and incident response are documented, enforced through our CI/CD pipeline, and audited as part of our ISO 27001 and CMMI Level 3 programs.
Because UnoPim's core codebase is open source, our security model gets an additional layer most closed platforms don't have: public code review. Anyone can inspect how authentication, permissions, and data handling are implemented — issues can be reported, tracked, and fixed in the open on GitHub.
Regular internal reviews, dependency audits, and release checks help the platform evolve safely as new modules — including our AI Agent tools — are added.
Here's how each area is implemented in UnoPim.
Role-Based Access Control (RBAC) lets you define exactly what each admin user, team, or API client can see and do. Granular ACL rules extend to AI agent tools, so automated actions respect the same permission boundaries as a human user.
UnoPim is built on Laravel 13 and PHP 8.4+, kept current with upstream framework security patches. Dependency updates, static analysis, and code review are part of every release before it ships.
API integrations use authenticated credentials and access controls to restrict access according to the configured permissions. Access can be restricted per client, per endpoint, and revoked if a key is compromised.
Product data, credentials, and secrets are encrypted in transit and at rest. Sensitive configuration values — API keys, SMTP credentials — are protected using encrypted credential storage.
UnoPim's Agentic PIM tools operate inside your existing ACL and role configuration — an agent can only read or modify catalog data that the application's authentication and authorization controls already permit for that user.
The UnoPim core is public on GitHub for inspection and review. Security-relevant code — auth, permissions, data access — can be reviewed by anyone, and vulnerabilities can be reported and tracked in the open.
UnoPim Cloud environments run on hardened, monitored infrastructure with network-level access controls isolating customer environments. Self-hosted deployments follow the same hardening guidance in our documentation.
Catalog data on UnoPim Cloud is backed up on a regular schedule with restore procedures tested as part of our operational reviews, reducing the impact of any single point of failure.
Security-relevant events are logged and reviewed, with a defined escalation path from detection through resolution and clear communication for any incident that affects your data.
Yes. UnoPim is an open-source PIM platform, with its source code publicly available for review and self-hosted deployment. This allows organizations to inspect the platform and its security-related implementation while maintaining control over their own infrastructure.
UnoPim's security information references ISO 27001, ISO 9001, SOC 2, and CMMI Level 3 alongside GDPR-aligned practices. These certifications and compliance references are presented as part of the security and hosting ecosystem, so the specific scope should be verified based on the deployment and hosting environment.
UnoPim supports encrypted communication through HTTPS, while sensitive AI provider credentials are stored using encrypted credential storage rather than plain text. Self-hosted deployments can also apply additional security controls such as SSL, firewall rules, IP restrictions, and secure protocols.
Yes. Administrators can control AI Agent access through role-based permissions, confidence thresholds, approval modes, agent steps, and other settings. Every AI Agent tool respects the user's ACL permissions, so the agent cannot perform actions beyond the permissions assigned to that user.
Yes. UnoPim can be installed and run on your own infrastructure using methods such as Composer, Docker, or a GUI-based installation. Self-hosting gives organizations greater control over their infrastructure, product data, access policies, and deployment environment.

From product creation to enrichment and categorization — everything runs through simple commands, not spreadsheets.
Error: Contact form not found.
If you have more details or questions, you can reply to the received confirmation email.
Back to Home