TestUnity LLC

    TestUnity LLC

    Securing Technology, Empowering Innovation

    Security Policy

    Our Commitment to Protecting Your Data and Systems

    At TestUnity LLC-FZ, security is not just our business—it's our foundation. As a leading cybersecurity company in the UAE, we hold ourselves to the highest standards of security and data protection. This Security Policy outlines our comprehensive approach to safeguarding your information and maintaining the integrity of our systems.

    Security Framework

    Our security framework is built on industry-leading standards and best practices:

    ISO 27001 Certified

    Information Security Management System (ISMS) compliance

    SOC 2 Type II

    Audited security, availability, and confidentiality controls

    PCI DSS Compliant

    Payment Card Industry Data Security Standard adherence

    NIST Framework

    Aligned with NIST Cybersecurity Framework

    Data Protection Measures

    Encryption

    • AES-256 encryption for data at rest
    • TLS 1.3 for data in transit
    • End-to-end encryption for sensitive communications
    • Encrypted backups with secure key management

    Access Controls

    • Multi-factor authentication (MFA) for all system access
    • Role-based access control (RBAC) with least privilege principle
    • Regular access reviews and permission audits
    • Automated access revocation for terminated accounts
    • Biometric authentication for critical systems

    Data Segregation

    • Logical separation of client data
    • Isolated environments for different security levels
    • Dedicated infrastructure for sensitive projects
    • Secure data disposal and sanitization procedures

    Infrastructure Security

    Network Security

    • Next-generation firewalls with intrusion prevention
    • Network segmentation and micro-segmentation
    • DDoS protection and mitigation
    • 24/7 network monitoring and threat detection
    • Regular vulnerability scanning and penetration testing

    Cloud Security

    • Secure cloud architecture with redundancy
    • Cloud security posture management (CSPM)
    • Container security and orchestration
    • API security and rate limiting
    • Regular cloud security assessments

    Physical Security

    • Tier III+ certified data centers
    • 24/7 security personnel and surveillance
    • Biometric access controls
    • Environmental monitoring and controls
    • Secure hardware disposal procedures

    Security Monitoring and Incident Response

    Continuous Monitoring

    • Security Information and Event Management (SIEM)
    • Real-time threat intelligence integration
    • Automated anomaly detection and alerting
    • Log aggregation and analysis
    • User behavior analytics (UBA)

    Incident Response

    • Dedicated Security Operations Center (SOC)
    • 24/7 incident response team
    • Documented incident response procedures
    • Regular incident response drills and tabletop exercises
    • Post-incident analysis and remediation
    • Transparent communication with affected parties

    Threat Management

    • Proactive threat hunting
    • Vulnerability management program
    • Regular security assessments and audits
    • Patch management and update procedures
    • Zero-day threat protection

    Application Security

    • Secure Software Development Lifecycle (SSDLC)
    • Static Application Security Testing (SAST)
    • Dynamic Application Security Testing (DAST)
    • Software Composition Analysis (SCA)
    • Code review and security testing before deployment
    • Web Application Firewall (WAF) protection
    • API security and authentication
    • Regular security updates and patches

    Personnel Security

    • Background checks for all employees
    • Mandatory security awareness training
    • Regular security training and certification programs
    • Strict confidentiality and non-disclosure agreements
    • Clean desk and clear screen policies
    • Secure remote work protocols
    • Regular security culture assessments

    Business Continuity and Disaster Recovery

    • Comprehensive business continuity plan (BCP)
    • Disaster recovery procedures with defined RTOs and RPOs
    • Regular backup procedures with offsite storage
    • Redundant systems and failover capabilities
    • Annual BCP testing and updates
    • Geographic redundancy for critical systems

    Third-Party Security

    We carefully vet all third-party vendors and service providers:

    • Security assessments before vendor onboarding
    • Contractual security requirements and SLAs
    • Regular vendor security reviews
    • Limited access based on business need
    • Monitoring of third-party access and activities

    Compliance and Audits

    We maintain compliance with relevant regulations and standards:

    • UAE Data Protection Law compliance
    • GDPR compliance for European clients
    • Regular internal security audits
    • Annual third-party security assessments
    • Penetration testing by independent security firms
    • Compliance reporting and documentation

    Responsible Vulnerability Disclosure

    We welcome responsible disclosure of security vulnerabilities. If you discover a security issue:

    • Email us at contact@testunity.ae
    • Provide detailed information about the vulnerability
    • Allow us reasonable time to address the issue before public disclosure
    • Do not exploit the vulnerability or access data beyond what's necessary to demonstrate the issue

    We commit to acknowledging your report within 48 hours and providing regular updates on remediation progress.

    Security Policy Updates

    We regularly review and update our security policies and procedures to address emerging threats and incorporate industry best practices. Material changes to this Security Policy will be communicated through our website and to our clients.

    Security Contact

    For security-related inquiries, vulnerability reports, or concerns:

    TestUnity LLC-FZ Security Team

    Dubai, United Arab Emirates

    Security Email: contact@testunity.ae

    General Contact: +971-521051429

    PGP Key: Available upon request for encrypted communications