Trust Center
Security & Trust
At Unleash IQ, security, privacy, and responsible AI are fundamental to how we design and deliver decision-intelligence solutions.
Our security approach combines governed cloud infrastructure, strong access controls, tenant isolation, encryption, monitoring, responsible AI practices, and clear accountability between Unleash IQ and our customers.
Customer Data Ownership
Customers retain ownership and control of their data. Unleash IQ processes customer data only to provide, configure, operate, secure, monitor, support, and maintain the agreed services.
We do not:
- Sell customer data
- Use customer data for unrelated commercial purposes
- Claim ownership of customer-specific data, reports, dashboards, business logic, models, workflows, prompts, outputs, or configurations
Responsible AI and Data Use
Unless expressly authorized in writing, Unleash IQ does not use customer data, prompts, outputs, workflows, business logic, reports, or customer-specific configurations to:
- Train shared AI models
- Fine-tune shared AI models
- Improve third-party foundation models
- Create commercial synthetic datasets
- Benchmark or commercialize AI models using customer-identifiable information
- Convert customer-confidential knowledge into general commercial functionality in a way that discloses or misuses that information
Approved AI Endpoints
Customer data is processed through approved enterprise, business, or private AI endpoints. We do not intentionally submit customer data to public consumer AI tools without customer authorization.
Access Control and Identity Management
Unleash IQ applies role-based access controls designed to ensure that users can access only the data, dashboards, workflows, and AI outputs authorized for their role and organization. Depending on the deployment, access controls may include:
- Role-based access control
- Multi-factor authentication
- Single sign-on
- Enterprise identity-provider integration
- SAML, OAuth, or OpenID Connect
- Administrative access controls
- User access logging
Customer Access Responsibilities
Customers are responsible for assigning appropriate roles, reviewing access, protecting credentials, and removing users who no longer require access.
Tenant Isolation
For multi-tenant SaaS services, Unleash IQ applies logical isolation controls designed to prevent unauthorized access between customers. These controls may include:
- Tenant-specific identifiers
- Application-level segregation
- Database-level access controls
- Tenant-aware APIs
- Segregated configurations
- Role-based access enforcement
- Access logging
- Storage-level logical separation
Encryption and Credential Protection
Unleash IQ applies commercially reasonable encryption and credential-protection controls. These may include:
- TLS 1.2 or higher for data in transit
- Encryption at rest for data stored in managed environments
- Secure storage of API keys, tokens, credentials, and connection strings
- Restricted access to secrets
- Protection against secrets appearing in logs
- Credential rotation where required
Logging and Monitoring
Unleash IQ maintains logging and monitoring controls for:
- User access
- Administrative activity
- Security-relevant events
- Configuration changes
- Data-integration jobs
- Workflow execution
- System availability
- Operational errors
- Support activity
- AI interactions
Use of Logs
Logs may be used for security monitoring, troubleshooting, incident investigation, auditability, compliance support, and service operations. Access to logs is restricted to authorized personnel.
AI Interaction Governance
Where enabled, AI interactions may be logged to support governance, auditability, security, troubleshooting, quality review, and compliance. AI interaction logs may include:
- User identifiers
- Timestamps
- Prompts or queries
- Generated outputs
- Model metadata
- Usage information
- Workflow or dashboard context
- Operational metadata
Safeguards for Sensitive Deployments
- Metadata-only logging
- Redaction or masking
- Restricted access to prompts and outputs
- Shorter retention periods
- Customer access to relevant audit records
- Disabling prompt or response storage where technically feasible
Infrastructure and Subprocessors
Unleash IQ may use approved providers to support:
- Cloud infrastructure
- Data storage
- AI model processing
- Monitoring and observability
- Cybersecurity
- Customer support
- Notifications
- Website and platform administration
- Other operational services
Provider Governance
We apply commercially reasonable diligence when selecting providers and require appropriate confidentiality, security, and data-protection commitments.
- A list of approved subprocessors where contractually required
- Relevant hosting-location information
- Notice of material subprocessor changes
- Approval rights for customer-specific subprocessors
Backup, Recovery, and Availability
Unleash IQ applies commercially reasonable backup and recovery controls for its SaaS services. Specific commitments may be defined in the applicable agreement or service-level agreement, including:
- Uptime targets
- Backup frequency
- Backup retention
- Recovery point objectives
- Recovery time objectives
- Support response times
- Disaster-recovery procedures
Vulnerability Management
Unleash IQ maintains practices designed to identify and manage vulnerabilities affecting its platform. These may include:
- Reviewing vulnerabilities affecting platform components
- Monitoring dependencies and infrastructure
- Applying security updates based on severity and risk
- Remediating material vulnerabilities within commercially reasonable timelines
- Supporting customer security reviews where agreed
Incident Response
Unleash IQ maintains procedures designed to identify, investigate, contain, remediate, recover from, and review security incidents. Our process may include:
- Detection and triage
- Investigation
- Containment
- Risk and impact assessment
- Remediation
- Recovery
- Customer notification
- Post-incident review
Notification
Where required by law or contract, affected customers will be notified without undue delay after Unleash IQ becomes aware of a confirmed security incident materially affecting customer data.
Data Retention and Secure Offboarding
Customer data is retained only for as long as necessary to provide the service and meet applicable contractual, legal, security, audit, and operational requirements. At the end of a customer relationship, Unleash IQ follows the agreed process for:
- Data export
- Data return
- Transition support
- Data deletion
- Offboarding
Backups
Backup copies may remain until they expire or are overwritten through standard backup cycles.
Shared Responsibility
Security is a shared responsibility between Unleash IQ and its customers.
Unleash IQ Responsibilities
- Operating and securing the managed SaaS platform
- Maintaining platform-level security controls
- Supporting role-based access control
- Maintaining tenant isolation
- Maintaining platform logging and monitoring
- Managing approved subprocessors
- Maintaining incident-response procedures
- Supporting agreed deletion and offboarding
- Applying platform updates and security patches
- Protecting customer data within Unleash IQ-managed environments
Customer Responsibilities
- Determining what data is appropriate to process
- Ensuring they have the required rights, notices, and permissions
- Managing user access, roles, and approvals
- Protecting user credentials
- Enforcing internal authentication policies
- Securing source systems, endpoints, and networks
- Reviewing AI-generated outputs before business use
- Promptly reporting suspected unauthorized access or misuse
Security Documentation
Detailed security documentation, customer-specific security terms, subprocessor information, and technical responses may be provided during the commercial, contractual, or security-review process.
Privacy
For information about how Unleash IQ collects, uses, shares, and protects personal information, please review our Privacy Policy.
Contact Us
Unleash IQ Private Limited, Sri Lanka
Website: www.unleashiq.ai
Email: support@unleashiq.ai
Please include “Security Inquiry” in the email subject line.