Universal Insights Research Group LLC is committed to maintaining the highest levels of data security and protecting the integrity of all information entrusted to us by our clients and research participants.
1. Infrastructure Security
Our infrastructure is hosted on industry-leading cloud providers with physical security controls, redundant systems, and 24/7 monitoring. Key measures include:
- All data is encrypted in transit using TLS 1.3 and at rest using AES-256 standards.
- Our systems are designed to align with SOC 2 Type II standards for security, availability, and confidentiality.
- Access to sensitive data is strictly controlled and monitored.
2. Access Control
We apply the principle of least privilege across all internal systems. Controls include:
- Least Privilege Principle: Employees are granted only the permissions necessary to perform their job functions.
- Multi-Factor Authentication (MFA): Required for all internal system access.
- Regular Audits: Access rights are reviewed quarterly and revoked promptly upon termination.
3. Application Security
Our QualityShield™ technology and platform are built with security in mind:
- Penetration Testing: We conduct annual third-party penetration testing and weekly vulnerability scans.
- Secure Development Lifecycle (SDLC): Security checks are integrated into our code deployment pipeline.
- Input Validation: All user inputs are sanitized to prevent SQL injection, XSS, and other common attacks.
4. Incident Response
We have established an Incident Response Plan (IRP) to address potential security events promptly. In the event of a data breach, we are committed to notifying affected individuals and regulatory bodies in compliance with applicable laws (including GDPR and US State Data Breach Notification Laws) within 72 hours of discovery.
5. Vendor Management
We rigorously vet all third-party vendors. Universal Insights Research Group LLC ensures that any sub-processors handling our data adhere to security standards equivalent to or higher than our own.
Report a Vulnerability
If you believe you have found a security vulnerability in any of our services, please report it to our security team immediately.
Contact Security Team