Skip to content

Trust center

Documented security. Unknowns made explicit.

This page separates documented safeguards, configuration choices and information that still needs confirmation before a contractual commitment.

Updated: August 23, 2026

Scope: Unitalk website, Workspace and Hermes environments described by the public code. Contractual terms and the selected configuration prevail.

Identity and access

Access controls

Status of identity, authorization and separation capabilities.

To document / To confirm

SSO / SAML

No SAML support or enterprise SSO policy is documented in the reviewed scope.

To document / To confirm

MFA

Factors, enrollment methods and mandatory MFA rules remain to be confirmed.

Available

Roles and permissions

Applications, data and tools are granted according to the role, mission and organization-defined permissions. Access can be limited or revoked.

Depending on configuration

Organization separation

Isolated environments and separate execution contexts are provided. The applicable isolation architecture is confirmed for each deployment.

Data and AI

Data lifecycle

Location, model flows and control over entrusted data.

Available

Hosting regions

The privacy policy states that Unitalk data is hosted in France. The region of a selected environment or provider is confirmed before deployment.

Available

Encryption

Data is stated to be encrypted in transit and at rest.

Depending on configuration

Model data flows

The organization selects authorized models and providers. Mission content is not used to train third-party models without explicit consent.

On request

Data deletion

Erasure rights can be exercised through hello@unitalk.ai. The operational process and precise timelines remain to be documented.

To document / To confirm

Processors

The privacy policy states that the list of processors and technical providers must be completed.

Continuity

Resilience and operations

Precise objectives depend on the plan and are not presumed.

Depending on configuration

Backups

Data covered by the selected policy may be backed up and restored. Frequency, scope and testing depend on the plan.

To document / To confirm

RPO / RTO

No quantified recovery point or recovery time objective is published.

To document / To confirm

Log retention

Connection logs and mission traceability are mentioned, but precise retention periods remain to be documented.

Depending on configuration

Incident management

Incident monitoring and support depend on the subscribed service level. Process, contacts and escalation times are confirmed in the offer.

Verification

Assurance and compliance

Missing evidence is never presented as established.

To document / To confirm

Penetration testing

Frequency, scope, provider and report availability are not documented.

To document / To confirm

Certifications

No verifiable Unitalk security certification is published in the reviewed scope.

On request

DPA

A Data Processing Agreement can be requested to define responsibilities, safeguards and processor terms.

Available

Hermes documentation

Official documentation describes command, file, session, container, secret and network controls in the open-source engine.

Clear responsibilities

Hermes protects the engine. Unitalk governs its use.

Security depends on the runtime, Unitalk configuration and rules selected by your organization.

01 · Hermes

Protects agent execution with command, file, session, secret and network controls.

02 · Unitalk

Configures missions, profiles, access, approvals and traceability within the plan scope.

03 · Your organization

Selects users, applications, data, models, permissions and human approvals.

Let’s review your actual scope.

Share your identity, hosting, data and continuity requirements. The review separates what is available, configurable and still to be confirmed.