Security Policy
Our Commitment to Protecting Your Data and Systems
At TestUnity LLC-FZ, security is not just our business—it's our foundation. As a leading cybersecurity company in the UAE, we hold ourselves to the highest standards of security and data protection. This Security Policy outlines our comprehensive approach to safeguarding your information and maintaining the integrity of our systems.
Security Framework
Our security framework is built on industry-leading standards and best practices:
ISO 27001 Certified
Information Security Management System (ISMS) compliance
SOC 2 Type II
Audited security, availability, and confidentiality controls
PCI DSS Compliant
Payment Card Industry Data Security Standard adherence
NIST Framework
Aligned with NIST Cybersecurity Framework
Data Protection Measures
Encryption
- AES-256 encryption for data at rest
- TLS 1.3 for data in transit
- End-to-end encryption for sensitive communications
- Encrypted backups with secure key management
Access Controls
- Multi-factor authentication (MFA) for all system access
- Role-based access control (RBAC) with least privilege principle
- Regular access reviews and permission audits
- Automated access revocation for terminated accounts
- Biometric authentication for critical systems
Data Segregation
- Logical separation of client data
- Isolated environments for different security levels
- Dedicated infrastructure for sensitive projects
- Secure data disposal and sanitization procedures
Infrastructure Security
Network Security
- Next-generation firewalls with intrusion prevention
- Network segmentation and micro-segmentation
- DDoS protection and mitigation
- 24/7 network monitoring and threat detection
- Regular vulnerability scanning and penetration testing
Cloud Security
- Secure cloud architecture with redundancy
- Cloud security posture management (CSPM)
- Container security and orchestration
- API security and rate limiting
- Regular cloud security assessments
Physical Security
- Tier III+ certified data centers
- 24/7 security personnel and surveillance
- Biometric access controls
- Environmental monitoring and controls
- Secure hardware disposal procedures
Security Monitoring and Incident Response
Continuous Monitoring
- Security Information and Event Management (SIEM)
- Real-time threat intelligence integration
- Automated anomaly detection and alerting
- Log aggregation and analysis
- User behavior analytics (UBA)
Incident Response
- Dedicated Security Operations Center (SOC)
- 24/7 incident response team
- Documented incident response procedures
- Regular incident response drills and tabletop exercises
- Post-incident analysis and remediation
- Transparent communication with affected parties
Threat Management
- Proactive threat hunting
- Vulnerability management program
- Regular security assessments and audits
- Patch management and update procedures
- Zero-day threat protection
Application Security
- Secure Software Development Lifecycle (SSDLC)
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Software Composition Analysis (SCA)
- Code review and security testing before deployment
- Web Application Firewall (WAF) protection
- API security and authentication
- Regular security updates and patches
Personnel Security
- Background checks for all employees
- Mandatory security awareness training
- Regular security training and certification programs
- Strict confidentiality and non-disclosure agreements
- Clean desk and clear screen policies
- Secure remote work protocols
- Regular security culture assessments
Business Continuity and Disaster Recovery
- Comprehensive business continuity plan (BCP)
- Disaster recovery procedures with defined RTOs and RPOs
- Regular backup procedures with offsite storage
- Redundant systems and failover capabilities
- Annual BCP testing and updates
- Geographic redundancy for critical systems
Third-Party Security
We carefully vet all third-party vendors and service providers:
- Security assessments before vendor onboarding
- Contractual security requirements and SLAs
- Regular vendor security reviews
- Limited access based on business need
- Monitoring of third-party access and activities
Compliance and Audits
We maintain compliance with relevant regulations and standards:
- UAE Data Protection Law compliance
- GDPR compliance for European clients
- Regular internal security audits
- Annual third-party security assessments
- Penetration testing by independent security firms
- Compliance reporting and documentation
Responsible Vulnerability Disclosure
We welcome responsible disclosure of security vulnerabilities. If you discover a security issue:
- Email us at contact@testunity.ae
- Provide detailed information about the vulnerability
- Allow us reasonable time to address the issue before public disclosure
- Do not exploit the vulnerability or access data beyond what's necessary to demonstrate the issue
We commit to acknowledging your report within 48 hours and providing regular updates on remediation progress.
Security Policy Updates
We regularly review and update our security policies and procedures to address emerging threats and incorporate industry best practices. Material changes to this Security Policy will be communicated through our website and to our clients.
Security Contact
For security-related inquiries, vulnerability reports, or concerns:
TestUnity LLC-FZ Security Team
Dubai, United Arab Emirates
Security Email: contact@testunity.ae
General Contact: +971-521051429
PGP Key: Available upon request for encrypted communications