The certifications Union holds and the frameworks its security practices align with.
Compliance and governance
Union.ai maintains industry-recognized certifications and aligns its security practices with established frameworks. The platform’s architecture (with strict data residency, tenant isolation, and control plane / data plane separation) inherently supports compliance requirements across regulated industries.
This section covers certifications, regulatory alignment, organizational security practices, and vulnerability management.
Certifications and Trust CenterUnion’s SOC 2 Type II certification, what the audit covers, and how to verify it through the Trust Center.HIPAA complianceHow the two-plane separation supports processing protected health information.GDPR alignmentHow the data residency model keeps EU customer data in the EU, and which control plane endpoints serve it.Standards complianceHow the private data plane architecture aligns with the ISO 27001 and CIS control frameworks.Shared responsibility modelWho owns which part of the stack in self-managed and BYOC deployments.Organizational securityBackground checks, security training, governance, and the secure development lifecycle behind the platform.Vulnerability managementDependency analysis, image scanning, penetration testing, patching, and incident response.