Open Source. Built Secure.

UnoPim, Built for Security

UnoPim is MIT licensed and open source, giving your team control over product data, infrastructure, and security.

Certifications & audits

Independently verified standards help demonstrate that security controls are built into UnoPim.

Security Backed by Independent Assurance

UnoPim's security posture is backed by recognized third-party frameworks that govern how we build, host, and support the platform — reviewed and renewed on a regular cycle rather than treated as a one-time badge.

ISO 27001

Our information security management practices are aligned with ISO 27001, covering how we govern access, infrastructure, and product development end to end.

CMMI Level 3

Engineering and organizational processes are assessed at CMMI Level 3 maturity, meaning development, testing, and release practices are defined, documented, and repeatable.

AICPA SOC 2

An independent SOC 2 Type II attestation provides assurance over controls within the scope defined by the SOC 2 report.

ISO 9001

Our quality management system is certified to ISO 9001, reinforcing consistent, documented processes across support, delivery, and product operations.

Cloud Hosting, Secured at Every Layer

UnoPim Cloud runs on hardened, monitored infrastructure with network isolation between customer environments — so your catalog data stays available, backed up, and out of reach of anyone but your team.

99.9%

Uptime target for UnoPim Cloud environments

24/7

Infrastructure monitoring and alerting

14 days

Maximum patch window for critical severity issues

Network segmentation

Each customer environment runs in its own isolated network, preventing lateral movement and containing potential threats.

Hardened by default

Servers ship with a reduced attack surface — minimizing unnecessary services to reduce vulnerabilities.

Backups & restore testing

Catalog data is backed up on a regular schedule, with restore procedures tested regularly to ensure data is recoverable.

Continuous monitoring

Infrastructure and application logs are watched around the clock to detect anomalies across the application layer.

Encryption everywhere

Data is encrypted in transit and at rest across every layer using AES-256 to protect sensitive product information.

Coordinated incident response

Security-relevant events follow a defined escalation plan, ensuring swift investigation and communication.

UnoPim Cloud secures

  • Hardened, monitored infrastructure with network segmentation
  • Encryption of data in transit and at rest on every layer
  • Scheduled backups with restore procedures tested regularly
  • Security patches backported to every supported release

You control

  • User accounts, roles, and permission assignments within the app
  • API credentials issued to your integrations, ERPs, and channels
  • Self-hosted server, database, and network configuration (if not Cloud)
  • Accuracy and classification of the product data you store

ISO 27001, CMMI Level 3, SOC 2, and ISO 9001 are publicly verifiable at webkul.com/about-us/certification. The SOC 2 report and further compliance documentation can be shared with you or your clients on request — ask our team →. Our vulnerability disclosure policy, response times and supported-version table are public at github.com/unopim/unopim/security/policy.

Security is a Program, not a Project

UnoPim's security practices are owned by our engineering and compliance leadership and reviewed on a continuous basis rather than revisited once a year. Policies covering access control, secure development, and incident response are documented, enforced through our CI/CD pipeline, and audited as part of our ISO 27001 and CMMI Level 3 programs.

Because UnoPim's core codebase is open source, our security model gets an additional layer most closed platforms don't have: public code review. Anyone can inspect how authentication, permissions, and data handling are implemented — issues can be reported, tracked, and fixed in the open on GitHub.

Regular internal reviews, dependency audits, and release checks help the platform evolve safely as new modules — including our AI Agent tools — are added.

3
Independent frameworks governing our program — ISO 27001, CMMI L3, SOC 2
3
Global regions supporting delivery and compliance — India, USA, Poland
Open
The core UnoPim source code is publicly available on GitHub for inspection and review

Defense across the Stack, from Login to Catalog

Here's how each area is implemented in UnoPim.

Identity & access management

Role-Based Access Control (RBAC) lets you define exactly what each admin user, team, or API client can see and do. Granular ACL rules extend to AI agent tools, so automated actions respect the same permission boundaries as a human user.

Application security

UnoPim is built on Laravel 13 and PHP 8.4+, kept current with upstream framework security patches. Dependency updates, static analysis, and code review are part of every release before it ships.

API & integration security

API integrations use authenticated credentials and access controls to restrict access according to the configured permissions. Access can be restricted per client, per endpoint, and revoked if a key is compromised.

Data encryption

Product data, credentials, and secrets are encrypted in transit and at rest. Sensitive configuration values — API keys, SMTP credentials — are protected using encrypted credential storage.

AI agent guardrails

UnoPim's Agentic PIM tools operate inside your existing ACL and role configuration — an agent can only read or modify catalog data that the application's authentication and authorization controls already permit for that user.

Open source transparency

The UnoPim core is public on GitHub for inspection and review. Security-relevant code — auth, permissions, data access — can be reviewed by anyone, and vulnerabilities can be reported and tracked in the open.

Hosting & infrastructure

UnoPim Cloud environments run on hardened, monitored infrastructure with network-level access controls isolating customer environments. Self-hosted deployments follow the same hardening guidance in our documentation.

Backup & continuity

Catalog data on UnoPim Cloud is backed up on a regular schedule with restore procedures tested as part of our operational reviews, reducing the impact of any single point of failure.

Incident response

Security-relevant events are logged and reviewed, with a defined escalation path from detection through resolution and clear communication for any incident that affects your data.

Frequently Asked Questions

Is UnoPim's source code publicly available

Yes. UnoPim is an open-source PIM platform, with its source code publicly available for review and self-hosted deployment. This allows organizations to inspect the platform and its security-related implementation while maintaining control over their own infrastructure.

What certifications does UnoPim hold

UnoPim's security information references ISO 27001, ISO 9001, SOC 2, and CMMI Level 3 alongside GDPR-aligned practices. These certifications and compliance references are presented as part of the security and hosting ecosystem, so the specific scope should be verified based on the deployment and hosting environment.

How does UnoPim handle encryption

UnoPim supports encrypted communication through HTTPS, while sensitive AI provider credentials are stored using encrypted credential storage rather than plain text. Self-hosted deployments can also apply additional security controls such as SSL, firewall rules, IP restrictions, and secure protocols.

Can I control what UnoPim's AI Agent is allowed to do

Yes. Administrators can control AI Agent access through role-based permissions, confidence thresholds, approval modes, agent steps, and other settings. Every AI Agent tool respects the user's ACL permissions, so the agent cannot perform actions beyond the permissions assigned to that user.

Does UnoPim support self-hosted deployments

Yes. UnoPim can be installed and run on your own infrastructure using methods such as Composer, Docker, or a GUI-based installation. Self-hosting gives organizations greater control over their infrastructure, product data, access policies, and deployment environment.

Free Forever Customisable Code Fast & Easy to Use
uno-jumbotron

Your Catalog. Fully Autonomous.

From product creation to enrichment and categorization — everything runs through simple commands, not spreadsheets.

success

Message Sent!

If you have more details or questions, you can reply to the received confirmation email.

Back to Home