Procurement Resources
Overview
This article provides an overview of Untitled’s approach to information security, infrastructure protection, vulnerability and patch management, data protection, and operational resilience. It is intended to assist enterprise customers, procurement teams, and security reviewers evaluating Untitled as a technology vendor.
Untitled provides a cloud-based Audience Platform used by organizations to perform identity resolution, data enrichment, audience building, and marketing activation workflows. The Platform processes website interaction signals, pseudonymous identifiers, and technical metadata in connection with these services.
Because the Platform operates on infrastructure that processes marketing and identity data, security, privacy, and operational reliability are foundational considerations in how Untitled designs and operates its systems.
Security Philosophy
Untitled’s security program is based on practical, layered controls designed to protect Platform infrastructure, customer data, and internal systems.
Core principles include:
Least-privilege access Access to infrastructure, production systems, and internal tools is granted based on role and limited to personnel whose responsibilities require it.
Defense-in-depth Security controls are implemented across infrastructure, application, network, and identity layers rather than relying on a single protective mechanism.
Secure cloud architecture Untitled’s Platform is deployed on Amazon Web Services (AWS) and leverages cloud security controls including encrypted storage, private networking, identity and access controls, and managed infrastructure services.
Continuous monitoring and maintenance Infrastructure dependencies and system components are monitored for vulnerabilities, operational issues, and required updates through automated tooling and internal review processes.
Information Security Program Scope
Untitled maintains an information security program designed to protect the confidentiality, integrity, and availability of our systems, Platform Services, and the information we process.
Our security practices include controls across the following areas:
Infrastructure and cloud security
Identity and access management
Encryption and data protection
Secure development and change management
Vulnerability management and patching
Logging, monitoring, and observability
Backup, recovery, and operational resilience
Incident response
Vendor and subprocessor management
Personnel and physical security
Additional information about Untitled's security practices and controls is available in our Information Security Policy.
Infrastructure Model
Untitled operates as a cloud-native SaaS platform hosted within Amazon Web Services (AWS).
Production infrastructure is deployed within AWS regions located in the United States and utilizes managed cloud infrastructure and redundancy controls to support system reliability.
Applicable production data stores are backed up automatically on a daily basis. Untitled also maintains write-ahead logging for applicable database systems, supporting point-in-time recovery at approximately five-minute intervals. Backup data is protected through appropriate encryption and access controls.
Encryption & Data Protection
Untitled protects data both in transit and at rest using widely adopted encryption standards.
Data in transit is encrypted using TLS 1.2 or higher.
Sensitive data stored in databases and object storage is encrypted using AES-256 encryption.
Encryption keys are managed using AWS Key Management Service (KMS).
Additional information about Untitled's data protection practices and controls is available in our Information Security Policy.
Identity & Access Management
Access to internal systems and infrastructure is governed through role-based access controls and centralized identity and access management.
Multi-factor authentication (MFA) is required for access to production systems, cloud infrastructure, administrative tooling, and other systems containing sensitive company or customer information.
User access privileges are reviewed periodically and are revoked without undue delay when access is no longer required, including upon employee off-boarding.
Additional information about Untitled's access and authentication controls is available in our Information Security Policy.
Observability & Patch Management
Untitled maintains a risk-based approach to identifying, prioritizing, and remediating security vulnerabilities and system errors across its infrastructure, applications, and dependencies. Issues are identified through automated scanning tools, monitoring of publicly disclosed vulnerabilities such as CVEs, vendor alerts, and internal observability and engineering processes.
Each issue is evaluated based on severity, exposure, and potential impact, with critical vulnerabilities prioritized for immediate remediation and lower-severity issues addressed through standard maintenance and release cycles. Where immediate fixes are not feasible, mitigating controls may be implemented to reduce risk.
Patches and updates are deployed through controlled processes, including CI/CD pipelines, managed cloud services, and version-controlled dependency updates. Untitled maintains ongoing visibility into vulnerabilities through automated issue tracking, alerting, and structured internal review processes.
Additional information about Untitled's observability systems and patch management processes is available in the Observability & Patch Management Policy.
Incident Response & Operational Resilience
Untitled maintains internal procedures for responding to security incidents and operational disruptions.
These procedures address incident reporting, escalation, investigation, containment, communication, remediation, and recovery activities.
In the event of a confirmed security incident affecting customer data, Untitled will notify affected customers in accordance with applicable legal requirements and the obligations defined in its Platform Services Agreement.
Additional information regarding incident response and operational resilience is available in our Information Security Policy.
Vendor & Subprocessor Management
Untitled uses a limited set of third-party infrastructure and service providers to support operation of the Platform.
Third-party providers are evaluated based on factors including the nature of the service, information involved, intended use, and applicable security, privacy, compliance, and operational considerations.
Where third-party subprocessors process Client Personal Data, they are subject to applicable contractual and data protection requirements. Untitled remains responsible for its subprocessors as provided in the Platform Services Agreement.
A current list of third-party subprocessors and additional information about vendor oversight is available in the Third-Party Subprocessors article.
Enterprise Procurement & Security Reviews
Untitled regularly works with enterprise customers that require vendor security, privacy, and procurement reviews. This documentation section is intended to support those processes by providing an overview of our systems, controls, standards, policies, subprocessors, and data-handling practices.
Questions
If additional documentation or questionnaire responses are required as part of a procurement process, please contact us at support@getuntitled.ai.
Last updated
Was this helpful?