Security & trust

Union data security and access controls

UnionStack brings tenant scope, identity, permissions, private file handling and secure integration patterns together so teams can connect their work without treating access as an afterthought.

Account access in practice

Manage sign-in methods and review account activity.

The connected account centre brings email verification, linked sign-in providers, password controls and recent sign-in history into view. These screenshots show a demonstration account.

Account settingsManage account details and connected sign-in methods.

Demonstration account shown with two-factor authentication disabled.

Sign-in activityReview where and how the account has signed in.

Demonstration sign-in history shown. Network locations are unavailable in this view.

A layered model

Security follows the record from request to storage.

A trustworthy union platform needs more than a secure sign-in. The organization context, the user’s authority, the requested record, any stored object and every integration path all participate in the decision.

01

Canadian data residency

Production services and customer data are hosted in Microsoft Azure Canada Central.

Confirm the selected Azure region and any external provider paths during procurement.
02

Tenant-scoped persistence

Reads are filtered to the active tenant and writes reject records that do not match tenant context.

Tenant context is part of the persistence boundary, not only a user-interface filter.
03

Permission-respecting access

Application and API operations remain subject to the authenticated user, tenant, roles and applicable record rules.

Connected records do not remove the distinct permissions around sensitive work.
04

Private object storage

Tenant-specific containers disable public access and validate object paths before storage operations.

Private documents are served through authorized application paths rather than public containers.
05

Application-layer encryption

Governed object content is protected with tenant-keyed authenticated AES-GCM envelopes before it is written to blob storage.

Key management and operating procedures remain part of the production deployment review.
06

Modern API authorization

Developer integrations use OAuth 2.0 authorization code flow with PKCE and tenant-aware access.

An API client does not become a path around application authorization.

Procurement review

Turn assurance into answerable questions.

Use these prompts to keep an evaluation specific to the environment, providers and workflows your union expects to operate.

Data location

Which data remains in Canada, and which enabled providers process data elsewhere?

Tenant boundary

How is organization context applied to reads, writes, files and background work?

Authorization

Which roles, scopes and record rules protect the workflow being evaluated?

Encryption

Where are transport, platform and application-layer protections applied?

Public and member access

How are public publishing and authenticated member experiences kept distinct?

Contractual assurance

Which requirements need current documentation or an executed agreement?

Shared responsibility

Configuration and operating practice matter.

Technology supplies boundaries. Administrators still decide who receives access, what is published and when those decisions need to be reviewed.

  1. 01

    Design roles

    Model responsibilities before assigning broad access.

  2. 02

    Review access

    Test with representative accounts and revisit access as duties change.

  3. 03

    Protect secrets

    Keep credentials, provider keys and recovery paths out of shared records.

  4. 04

    Control publishing

    Verify public and member visibility before promoting content.

  5. 05

    Reassess

    Repeat the review when workflows, integrations or providers change.

Buyer questions

Direct answers, with their limits.

Confirm environment-specific controls and contractual requirements during procurement.

Where is customer data hosted?

UnionStack production services and customer data use Microsoft Azure Canada Central for Canadian data residency. Enabled external providers should be reviewed separately.

How are stored documents protected?

Tenant-specific object containers disable public access, validate paths and can apply tenant-keyed authenticated encryption before storage.

Does an API bypass application permissions?

No. API requests operate with tenant and user context and remain subject to the applicable authorization rules.

Does connected data mean every user can see everything?

No. Relationships can remain connected while module, role and record-level rules restrict who may access sensitive information.

How are integration secrets handled?

Secrets belong in protected server-side configuration and key-management boundaries, never in public content or browser bundles.

Are public sites and member experiences the same boundary?

No. Public publishing and authenticated member access are distinct choices and should be tested independently.

Does UnionStack claim a certification here?

No certification is claimed without separate current evidence. Request documentation for any contractual, regulatory or assurance requirement.

Next step

Bring your security requirements into the evaluation.

Try a real workflow with the 30-day trial, or request a guided walkthrough with UnionStack.

Credit card required. Automatic billing after 30 days.