Security & Compliance
Clear protections for your accounts, conversations and team—backed by independently assessed Unipile security controls.
Effective and last updated: 15 September 2026
Independent assurance
Nilyo is operated by Unipile SAS. Unipile is SOC 2 Type II certified, GDPR compliant and CASA Tier 2 certified. The SOC 2 report, DPA, security whitepaper and penetration-test summary are available on request through the Unipile Trust & Security page.
Your accounts remain yours
- You choose which professional accounts to connect and which agent or connector may use them.
- Your provider passwords and connection credentials are never shown to an agent or another Team member.
- Company billing does not give administrators access to members’ messages, email or calendars.
- You can disconnect an account or revoke an agent’s access whenever needed.
Protected by default
- Data is encrypted in transit and sensitive stored data is encrypted at rest.
- Access is limited to what is necessary to operate and support the service.
- Email verification, secure sign-in and optional two-factor authentication help protect your workspace.
- Monitoring, code review, vulnerability scanning and independent penetration testing support the security program.
You stay in control of agent actions
- An agent can use only the accounts you have connected and authorized.
- Searching and reading do not silently authorize sending, inviting or deleting.
- Consequential actions remain explicit, and ambiguous recipients or accounts must be clarified before acting.
- Your connected provider’s own permissions and safeguards continue to apply.
We minimize stored data
We keep the account, subscription and connection information needed to provide and secure the service. Private communications are accessed only when a user, authorized agent or installed connector requests a supported action. They are not sold or used for advertising.
Account disconnection, failed-payment recovery and deletion periods are explained in the Privacy Policy.
Reporting and documentation
Report a suspected security or personal-data incident to start@unipile.com and copy dpo@unipile.com when personal data may be involved. Do not include passwords, provider tokens or other secrets in the initial email.
Certification describes the audited Unipile control environment; it does not remove a customer’s responsibility to configure its agents, ATS/CRM permissions and provider usage lawfully.