Security Policy & Responsible Disclosure — Unilyx Technologies
Effective Date: 1 January 2025 | Last Updated: 29 September 2026 | Version: 1.0
At Unilyx Technologies ("Unilyx", "we", "our"), security is not an afterthought — it is the cornerstone of our engineering philosophy. We develop software that powers small businesses, pharmacies, clinics, and educational institutions across India. Protecting the confidential data, records, and operations entrusted to us is our highest commitment.
This document describes our security architecture, data protection controls, and our Vulnerability Disclosure Policy (Responsible Disclosure Program).
1. Security Architecture & Infrastructure Safeguards#
- Transport Layer Security (TLS 1.3): All external web traffic and internal microservice communications are enforced via HTTPS using modern TLS 1.3 encryption with strict HTTP Strict Transport Security (HSTS) headers.
- Cryptographic Standards at Rest: Sensitive stored records and database snapshot backups are encrypted using industry-standard AES-256 encryption.
- Tier-4 Cloud Infrastructure: Our backend microservices and databases are hosted on certified enterprise cloud providers (MongoDB Atlas, AWS, Render) featuring biometric physical security, redundant power grids, and 24/7 automated monitoring.
- Network Firewalls & DDoS Mitigation: Ingress traffic is shielded by intelligent Web Application Firewalls (WAF), rate-limiting algorithms, and distributed denial-of-service (DDoS) mitigation layers.
2. Application & Authentication Security#
- Credential Protection: Passwords are never stored in plaintext. We utilize adaptive hashing algorithms (bcrypt with high work factors) to protect credentials against dictionary and rainbow table attacks.
- Multi-Tenant Logical Isolation: For our SaaS platforms (such as SchoolSaaS), tenant records are strictly compartmentalized using isolated database queries and cryptographic tenant IDs, eliminating any risk of cross-tenant data leakage.
- Brute-Force & Rate Limiting: Automated IP throttling and temporary account locks activate following repeated failed authentication attempts.
- Automated Daily Backups: Automated, encrypted point-in-time snapshots of databases are taken daily with verifiable disaster recovery and rollback procedures.
3. Data Protection Compliance#
Our security controls comply with:
- The Digital Personal Data Protection Act, 2023 (DPDPA 2023)
- The Information Technology Act, 2000 (and amendments)
- CERT-In Cyber Security Directions (2022)
In the event of a verified security incident affecting client records, Unilyx commits to notifying affected stakeholders and the Indian Computer Emergency Response Team (CERT-In) within mandatory statutory timelines (72 hours).
4. Vulnerability Disclosure Program (Responsible Disclosure)#
We warmly welcome reports from ethical security researchers, penetration testers, and engineers who help us keep our users safe.
Safe Harbor Guarantee
If you discover a security vulnerability in our public web properties or platforms and conduct your research in good faith in compliance with this policy:
- We will not initiate legal action against you or request law enforcement investigation.
- We will work collaboratively with you to understand, validate, and remediate the vulnerability swiftly.
- We will publicly acknowledge your contribution in our Security Hall of Fame (if desired).
Scope
- Target Domain:
unilyx.comand verified subdomains (*.unilyx.com) - Core Web APIs and public endpoints
Out of Scope & Strictly Prohibited
- Denial of Service (DoS / DDoS) attacks against our infrastructure.
- Social engineering, phishing, or physical attacks against Unilyx employees or facilities.
- Accessing, modifying, or downloading private customer records or data belonging to another party. (If you discover a flaw exposing user data, stop testing immediately and report it).
- Automated vulnerability scanners generating abusive traffic volumes.
How to Report a Vulnerability
Send a comprehensive vulnerability report via email to our security response team:
- Security Contact: unilyxofficial@gmail.com
- Subject Line:
[Security Vulnerability Report] - - Please Include:
- Detailed step-by-step reproduction instructions or a Proof of Concept (PoC).
- Potential impact and severity assessment.
- Screenshots or network payloads demonstrating the flaw without altering production data.
- Your name or handle if you wish to be credited.
Our Response Timeline
- Initial Acknowledgment: Within 24 hours of submission receipt.
- Triage & Validation: Within 48 hours.
- Remediation & Patch Deployment: Critical vulnerabilities are patched within 72 hours of verification.
- We ask that you maintain mutual confidentiality and allow us reasonable time to resolve the issue before any public disclosure.
Statutory Grievance & Compliance Redressal
In compliance with the Information Technology Rules, 2021 and the Digital Personal Data Protection Act, 2023, you can reach out directly to our Grievance Officer regarding any data, privacy, or terms queries:
Official Email
unilyxofficial@gmail.comDirect Telephone
+91 6202591456Registered Office: Unilyx Technologies, Patna, Bihar, India. Acknowledgment provided within 24 hours; formal resolution within 15 working days.