USATII MEDIA

Security & privacy

Usatii is committed to protecting client data and the systems that use it. Our platforms prioritize robust security and privacy, tested by a team focused on practical safeguards.

Keeping your data secure

For your team

You control how your operational data is used.

  • Access is designed around role-based controls and capability statements.
  • Authentication and ACLs protect sensitive information.
  • Organizations decide who can view, change, export, or remove data.
  • Activity can be logged so important changes remain attributable.
  • Client data is not sold or used to train public AI models unless specified in a sovereign client context.

For your business

Safeguards for systems running proprietary business workflows.

  • Security requirements are defined around each system's risk profile.
  • Data is encrypted in transit and protected at rest by our infrastructure providers.
  • 3rd-party integrations are scoped to the access they need.
  • Backups, recovery, and availability are considered for mission-critical workflows.
  • We document ownership and handoff so your business stays yours.

Security practices & alignment

We use established security and privacy frameworks to guide how systems are designed, built, and maintained. The controls applied to each project depend on its data, users, integrations, and operational risks.

Review our privacy policy or security guide for more details regarding our approach.

Our standards

OWASP application security guidance

Our application review and development practices follow established OWASP guidance for common web application risks.

NIST Cybersecurity Framework

We use the NIST framework as a practical reference for identifying, protecting, detecting, responding to, and recovering from security events.

CIS Controls

Infrastructure and account safeguards are informed by prioritized CIS Controls appropriate to the size and risk of your implementation.

SOC 2-ready architecture

Systems can be designed with access control, logging, change management, and evidence collection needed to support or complete compliance programs.

Privacy-by-design principles

We minimize collection, define purpose and retention, and keep data access understandable throughout the system lifecycle. Sovereign data usage is a first-class ability of our company and is available upon request.

Security at every step

Defense in depth

Infrastructure combines identity controls, encrypted transport, scoped permissions, and provider-level safeguards instead of relying on one boundary.

Responsible development

Security is considered during architecture, implementation, review, and deployment—not added after a system is complete.

Operational controls

Role-based access, audit history, approval gates, and data ownership are designed around how your organization works.

Reporting security issues

Potential vulnerabilities are investigated directly and handled according to their severity, affected data, and impact.

More resources