Security & Trust

Secure from the infrastructure up.

UnityTrip is built for enterprise customers who require transparency, control, and rigorous data protection. Security is designed into the platform from the infrastructure up — and the foundation is Microsoft Azure.

Where is UnityTrip hosted?

UnityTrip runs on Microsoft Azure. Azure's infrastructure is independently audited and maintains SOC 2, ISO 27001, and a range of other internationally recognised certifications. By building on Azure, UnityTrip inherits enterprise-grade physical, network, and platform security as the foundation of the service.

Built on Microsoft Azure

UnityTrip is a member of the Microsoft AI Cloud Partner Program (ISV Success) and is available on the Microsoft Azure Marketplace.

Microsoft Azure — certified infrastructure

SOC 2 ISO 27001 ISO 27018 GDPR

These certifications are held by Microsoft Azure, the platform UnityTrip is built on. Verify Azure's current attestations at the Microsoft Trust Center.

UnityTrip inherits the assurance of Azure's certified infrastructure. Where an organisation requires UnityTrip's own audit documentation, please get in touch.

How does UnityTrip protect customer data?

  • Encryption — data is encrypted in transit.
  • Role-based access control (RBAC) — users and operations staff access only what they are authorised to.
  • Zero-trust architecture — every request is authenticated and authorised, with no implicit trust between components.
  • Infrastructure as code — every environment is reproducible and every configuration change is auditable.
  • Event-sourced audit trail — every booking, change, and approval is recorded as an immutable event, giving a complete, tamper-evident history.
  • Credential management for staff, contractors, and dependents is handled securely and flexibly, reflecting shifting roles and travel privileges.

Is UnityTrip suitable for security-conscious enterprises?

Yes. UnityTrip runs in production for organisations with demanding compliance and operational requirements, including in regulated sectors such as energy and resources. The architecture is designed to support vendor management, travel-policy compliance, and full data oversight — so security and operational control reinforce each other rather than trading off.

How is customer data isolated between tenants?

Each client is an isolated tenant, provisioned automatically through infrastructure as code — your data never shares a boundary with another organisation's. Because every tenant is provisioned as code on Azure, deployments are reproducible, auditable, and can be aligned to an organisation's data-residency requirements.

Can UnityTrip detect a rogue identity inside a trusted network?

Yes — and this is where architecture matters. A single rogue automation inside a customer's trusted network — a misconfigured script, or increasingly a misbehaving AI agent — can hammer a platform many times past its normal baseline. A system that relies on perimeter security alone faces a binary choice: block all of the customer's traffic, or stay open and go down. UnityTrip's per-identity observability isolates the offending identity in real time, down to the individual account, so the disruptor is stopped without blocking the customer — while autoscale headroom absorbs the surge. The API face of this — the security manifest, per-identity activities, and role endpoints — is documented in the API reference.

How does UnityTrip stay available during demand surges?

Disruption is when a travel platform matters most — and when load spikes hardest. UnityTrip is event-sourced and natively distributed: work is queued and streamed rather than contended in a single database, so the platform is designed to absorb surges of 10 to 1000 times normal activity and degrade gracefully rather than fall over. State is replayable from the event stream, and live availability is published at platformstatus.unitytrip.com.

Does UnityTrip use AI to make booking decisions on customer data?

No. UnityTrip's doctrine is frontier AI at build time, determinism at run time. AI amplifies the consultancy that designs and configures each client's policy; the engine that decides bookings is deterministic, auditable, and explainable — the same booking gets the same answer every time, with the rule that decided it attached. Where an AI assistant answers traveller questions, it is grounded in the client's own managed policy documents, and it remains a client of the deterministic policy layer — never the judge. No AI guesses at booking time.

Documentation & due diligence

For detailed information on our security practices, or to request documentation for a vendor security review, get in touch.

Talk to us

Live system availability: platformstatus.unitytrip.com →