Data protection and customer segregation
Customer data lives in AWS RDS with encryption at rest, and is logically segregated per customer — no shared tables across accounts. Access is controlled through the UbiVu asset management platform's role-based access control (RBAC), so operational data reaches only the personnel authorized to see it.
Ubicquia generally does not collect personally identifiable information (PII). Data collection is limited to what's operationally required to deliver the service — a design choice that reduces regulatory exposure and privacy risk for customers and their end users.
Vulnerability management and incident response
The security program continuously monitors for new threats using automated scanning, internal security audits, and periodic external penetration testing. Identified vulnerabilities are logged, prioritized, assigned to an owner, and tracked through remediation. Incident response follows a documented process — pre-designated ISIRT (Integrated Security Incident Response Team) stakeholders, root cause analysis for every incident, and remediation lessons folded back into the ISMS.
Vendors and third parties are evaluated during onboarding for cybersecurity posture and re-reviewed at contract renewal or annually based on engagement risk. All vendors must comply with Ubicquia's cybersecurity commitments as a condition of engagement.