> For the complete documentation index, see [llms.txt](https://docs.getuntitled.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.getuntitled.ai/misc/procurement-resources/information-security-policy.md).

# Information Security Policy

### 1. Purpose

Untitled, LLC ("Untitled") maintains an information security program designed to protect the confidentiality, integrity, and availability of information processed through Untitled's systems and Platform Services.

This policy describes the administrative, technical, organizational, and physical safeguards Untitled uses to protect Client Data, Personal Data, Untitled systems, and other confidential or sensitive information from unauthorized access, disclosure, alteration, loss, misuse, or destruction.

Untitled's security practices are designed to support the operation of a cloud-based Software-as-a-Service platform and the identity resolution, enrichment, audience, intent, activation, integration, API, and related services provided through the Untitled Platform.

### 2. Scope

This policy applies to:

* Untitled's production infrastructure and Platform Services;
* systems and applications used to process, transmit, or store Client Data, Personal Data, or other confidential information;
* personnel with authorized access to Untitled systems or information;
* third-party service providers and subprocessors where applicable; and
* data received or transmitted through authorized Platform interfaces, integrations, APIs, tags, data connections, and destinations.

Security requirements are applied based on the nature of the system, information being processed, level of access, and associated operational or security risk.

### 3. Security Governance and Responsibility

Responsibility for information security is shared across Untitled's technical and operational functions.

Personnel responsible for systems, infrastructure, applications, and business operations are expected to implement and maintain security controls appropriate to their responsibilities. Security considerations are incorporated into infrastructure management, software development, access administration, vendor management, incident response, and ongoing Platform operations.

Security policies, procedures, and controls are reviewed and may be updated as Untitled's services, technologies, risks, contractual obligations, and legal requirements evolve.

### 4. Risk Management

Untitled takes a risk-based approach to information security.

Security risks are evaluated in connection with system architecture, infrastructure and application changes, vulnerability management, third-party services, operational events, and other activities where security considerations may arise.

Identified risks are evaluated according to factors such as likelihood, potential impact, affected systems or information, exposure, and available mitigating controls. Remediation and other risk-response activities are prioritized accordingly.

### 5. Information Protection

Untitled applies safeguards appropriate to the sensitivity and purpose of the information it processes.

Client Data and Client Personal Data are treated as confidential information and are protected from unauthorized access, use, or disclosure. Access is limited to authorized personnel and systems where required to provide, operate, maintain, secure, or support the Platform Services.

Untitled processes Client Personal Data on behalf of its clients and in accordance with applicable agreements, documented client instructions, and applicable law.

Untitled does not sell or share Client Personal Data.

### 6. Access Control and Authentication

Untitled applies access controls designed to restrict system and information access to authorized users.

Core access control practices include:

* applying least-privilege principles when granting access to infrastructure, production systems, internal tools, and information;
* granting access based on job responsibilities and business need;
* maintaining individual user credentials rather than shared user access where reasonably practicable;
* requiring multi-factor authentication for access to production systems, cloud infrastructure, administrative tooling, and other sensitive systems;
* restricting access to Personal Data and Client Data to authorized personnel;
* reviewing and modifying access as responsibilities change; and
* revoking access without undue delay when it is no longer required.

Remote access to critical infrastructure requires secure access controls, including VPN access when authorized personnel are not connected through Untitled's office network.

Clients are responsible for maintaining the confidentiality of credentials issued to their authorized users and for ensuring that Platform access is limited to appropriate personnel.

### 7. Encryption and Data Transmission

Untitled protects data in transit and at rest using industry-standard encryption mechanisms.

Data transmitted to or from supported Untitled systems is protected using TLS 1.2 or higher where applicable.

Sensitive information stored within production databases and object storage is encrypted at rest using AES-256 encryption or equivalent protections provided through Untitled's cloud infrastructure.

Encryption keys, credentials, secrets, and other sensitive authentication materials are managed through access-controlled systems and are not intentionally exposed through application interfaces or public repositories.

### 8. Cloud Infrastructure and Network Security

Untitled operates as a [cloud-native SaaS platform](/misc/procurement-resources/platform-data-flows.md). Core Platform production infrastructure and identity resolution systems are hosted within Amazon Web Services ("AWS") in the United States.

Untitled does not operate on-premises production infrastructure or data centers.

Untitled applies technical controls designed to protect cloud infrastructure and network-accessible systems, including:

* authentication and authorization controls;
* network access restrictions;
* firewalls and other network security mechanisms;
* separation of access privileges based on role and responsibility;
* monitoring of production infrastructure and services;
* encryption of data transmitted across supported network connections; and
* controls intended to reduce unauthorized access to production resources.

Access to production infrastructure is restricted to personnel with an authorized operational need.

### 9. Secure Development and Change Management

Untitled incorporates security considerations into the development, deployment, maintenance, and operation of Platform software and infrastructure.

Software and infrastructure changes are developed, reviewed, tested, and deployed through managed development and release processes appropriate to the nature of the change.

Development, testing, and production activities are appropriately separated, and production changes are managed through established change-management processes.

Untitled considers recognized secure-development practices, including applicable OWASP guidance, when developing and maintaining Platform services.

### 10. Vulnerability and Patch Management

Untitled maintains vulnerability and patch management processes designed to identify, evaluate, prioritize, and remediate software vulnerabilities, security weaknesses, and required updates.

Untitled follows a risk-based approach to remediation. Factors considered may include:

* vulnerability severity;
* likelihood of exploitation;
* system exposure;
* affected information or functionality;
* availability of a vendor patch or remediation;
* operational impact; and
* availability of compensating or mitigating controls.

Untitled performs periodic vulnerability scanning of applicable systems. Identified vulnerabilities are prioritized according to severity and risk, with critical and high-severity vulnerabilities receiving accelerated remediation.

Zero-day and actively exploitable vulnerabilities are evaluated promptly and addressed based on their potential impact and exposure.

Where immediate remediation is not reasonably feasible, Untitled may implement mitigating controls while a permanent correction is developed, tested, or made available.

Additional information is available in Untitled's Observability & Patch Management Policy.

### 11. Logging, Monitoring, and Observability

Untitled maintains logging and [observability capabilities](/misc/procurement-resources/observability-and-patch-management-policy.md) to support the operation, security, troubleshooting, and performance of the Platform.

Depending on the applicable system, logs may include authentication activity, user and administrative actions, API activity, diagnostic information, application events, infrastructure activity, performance information, and security-related events.

Monitoring and observability information may be used to:

* identify system errors or abnormal behavior;
* detect potential security events;
* troubleshoot Platform issues;
* evaluate system performance and availability;
* support vulnerability and patch management;
* investigate suspected incidents; and
* maintain appropriate audit and operational records.

Access to security and operational logging systems is restricted to authorized personnel.

### 12. Backup, Recovery, and Availability

Untitled maintains backup and recovery capabilities designed to protect production data and support restoration following an operational failure, security event, or other disruption.

Applicable production data stores are backed up automatically on a daily basis. Untitled also maintains write-ahead logging for applicable database systems, supporting point-in-time recovery at approximately five-minute intervals.

Backup and recovery controls include:

* automated daily backups of applicable production data stores;
* point-in-time recovery capabilities for applicable database systems;
* encryption and access controls appropriate to backup and recovery data;
* monitoring of backup status;
* redundancy and recovery mechanisms designed to reduce the risk of data loss and service interruption; and
* procedures for restoring data and Platform functionality following an operational failure or other disruption.

Backup configurations and retention periods may vary based on the applicable system, data store, service criticality, and underlying cloud infrastructure.

Untitled maintains recovery procedures appropriate to the nature and criticality of its production systems.

### 13. Security Incident Response

Untitled maintains procedures for identifying, reporting, investigating, containing, remediating, and documenting suspected or confirmed security incidents.

A Security Incident includes actual or suspected unauthorized access, use, disclosure, modification, loss, or destruction of Personal Data or Client Data, or another compromise of safeguards protecting that information.

When a Security Incident involving Client Data or Client Personal Data occurs, Untitled will:

1. investigate the nature and scope of the incident;
2. take appropriate steps to contain and remediate the incident;
3. notify affected clients without undue delay after becoming aware of the Security Incident, as required by the applicable agreement and law;
4. provide reasonably requested information concerning the incident, affected information, and remediation activities;
5. reasonably cooperate with affected clients in connection with their response obligations; and
6. evaluate and implement appropriate measures intended to reduce the likelihood of recurrence.

Security incidents are evaluated according to their severity, scope, affected systems or information, and potential operational, contractual, privacy, or security impact.

### 14. Third-Party Service Providers and Subprocessors

Untitled uses third-party service providers and subprocessors to support functions such as cloud hosting, infrastructure, authentication, security, communications, analytics, payments, customer support, and other Platform or business operations.

Third-party providers are evaluated based on factors including the nature of the service, information involved, intended use, and applicable security, privacy, compliance, and operational considerations.

Where a subprocessor processes Client Personal Data in connection with the Platform Services:

* the subprocessor is subject to applicable contractual and data protection requirements;
* Untitled requires data protection obligations appropriate to the services being provided;
* Untitled provides reasonable advance notice of new subprocessors where required by the applicable client agreement; and
* Untitled remains responsible for its subprocessors as provided by the Platform Services Agreement.

Untitled maintains a [current list of applicable third-party subprocessors](/misc/procurement-resources/third-party-subprocessors.md) within its Procurement Resources documentation.

### 15. Data Retention and Secure Deletion

Untitled retains information only for as long as reasonably necessary for the applicable business, operational, contractual, security, or legal purpose.

Client Personal Data is retained and deleted in accordance with the applicable client agreement and legal requirements.

Upon expiration or termination of applicable Platform Services, Untitled will, at the client's option and subject to applicable contractual terms:

* return Client Personal Data in a commonly used electronic format; or
* securely delete applicable Client Personal Data from Untitled systems.

Information required to be retained by law may be retained for the required period and will remain subject to appropriate protections.

Limited suppression or opt-out records may also be retained where necessary to continue honoring privacy choices. Aggregated or de-identified information may be retained where permitted by applicable agreements and law.

### 16. Privacy and Data Protection

Information security and privacy protections are applied together as part of Untitled's data protection practices.

For Client Personal Data processed through the Platform:

* the client generally acts as the business, controller, or equivalent role under applicable privacy law;
* Untitled generally acts as the service provider, processor, or equivalent role;
* Untitled processes Client Personal Data to provide the Platform Services and in accordance with applicable client instructions and agreements;
* Untitled does not sell or share Client Personal Data; and
* Untitled maintains safeguards designed to protect Client Personal Data from unauthorized access, disclosure, alteration, loss, misuse, or destruction.

Untitled's identity graph and identity resolution services are designed for United States records and U.S.-based audiences, and core production infrastructure supporting these services is hosted in the United States.

Additional information regarding Untitled's collection, use, disclosure, and protection of Personal Data is available in the Untitled [Privacy Policy](https://getuntitled.ai/privacy-policy/) and [Platform Services Agreement](https://getuntitled.ai/platform-services-agreement/).

### 17. Personnel Security and Security Awareness

Personnel with access to Untitled systems or confidential information are expected to follow applicable information security, confidentiality, access control, and data protection requirements.

Untitled applies access restrictions based on personnel responsibilities and limits production or sensitive system access to individuals with an authorized business need.

Personnel are expected to:

* protect authentication credentials;
* protect Client Data and other confidential information from unauthorized access or disclosure;
* use approved methods for accessing critical infrastructure;
* follow applicable security and data handling requirements; and
* promptly report suspected security incidents or vulnerabilities through appropriate internal channels.

Untitled provides personnel with security and data protection guidance and training appropriate to their responsibilities.

Access to Untitled systems is revoked without undue delay following termination or when access is otherwise no longer authorized.

### 18. Physical Security

Untitled's critical production systems and infrastructure are cloud-based and are not hosted within Untitled's office facilities.

Physical protection of cloud infrastructure is provided through Untitled's applicable infrastructure and hosting providers.

Access to Untitled office space is restricted through building and suite access controls. Personnel are expected to protect company-issued devices and other resources from unauthorized physical access, loss, or theft.

Company-managed laptops used to access sensitive systems are protected using full-disk encryption.

### 19. Client Security Responsibilities

Security of the Platform also depends on appropriate actions by clients and authorized users.

Clients are responsible for:

* maintaining the confidentiality of Platform usernames, passwords, API keys, and other access credentials;
* restricting access to authorized users;
* promptly removing access that is no longer required;
* using the Platform only for lawful and authorized purposes;
* maintaining appropriate privacy notices and consent mechanisms where required;
* maintaining a privacy policy and consent management or cookie consent solution where the Untitled Identity Tag is deployed;
* protecting Client-controlled systems and integrations connected to Untitled;
* promptly reporting suspected unauthorized access, security issues, errors, or anomalies; and
* refraining from attempts to bypass Platform security controls, probe systems for vulnerabilities without authorization, or otherwise interfere with Platform security or operation.

Client-selected third-party destinations and integrations may be subject to the security and privacy practices of those third parties after information is transmitted at the client's direction.

### 20. Policy Review and Maintenance

Untitled periodically reviews this policy and its underlying security practices and may update them to reflect changes in:

* security risks and threats;
* technologies and Platform architecture;
* business operations;
* security controls and procedures;
* legal and regulatory requirements;
* contractual obligations; and
* third-party services.

Material changes may be incorporated into this policy or related Procurement Resources documentation as appropriate.

### 21. Related Resources

Additional information regarding Untitled's security, privacy, infrastructure, subprocessors, and data processing practices is available through the following resources:

* [Platform Services Agreement](https://getuntitled.ai/platform-services-agreement/)
* [Privacy Policy](https://getuntitled.ai/privacy-policy/)
* [Procurement Resources](/misc/procurement-resources.md)
* [Observability & Patch Management Policy](/misc/procurement-resources/observability-and-patch-management-policy.md)
* [Third-Party Subprocessors](/misc/procurement-resources/third-party-subprocessors.md)
* [Platform Data Flows](/misc/procurement-resources/platform-data-flows.md)

### 22. Additional Information

This policy provides a **high-level description of Untitled's current information security practices** and is intended to assist clients and prospective clients with security, procurement, and vendor review processes.

This policy does not replace or modify the terms of an applicable [Platform Services Agreement](https://getuntitled.ai/platform-services-agreement/), order form, data processing agreement, or other written agreement between Untitled and a client. In the event of a conflict, the applicable executed agreement will control.

### Questions

If you have questions regarding Untitled's information security, privacy, or procurement practices, please contac&#x74;**:** **<support@getuntitled.ai>**


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.getuntitled.ai/misc/procurement-resources/information-security-policy.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
