Security at CloudUnifi
Customers trust us with the configuration of their networks. This page explains how we protect the service and your data. A more detailed Security Overview document for vendor security reviews (CIS, ISO 27001 supplier assessments, and similar) is available on request via support.
Hosting and data centers
Your UniFi controller runs on dedicated servers operated by our datacenter partner, OVHcloud, in Australia, Canada, France, Germany, the UK, and the US. OVHcloud provides physical security, power, and environmental controls at these facilities, and holds certifications including ISO/IEC 27001, ISO/IEC 27017, and ISO/IEC 27018 covering the data centers and dedicated server services we use. Every controller runs in its own isolated container. Customers do not share an application process or data store.
Network protection
-
Always-on DDoS mitigation and an edge network firewall in front of every server.
-
Host firewalls are default deny. Only the ports the UniFi service needs are open.
-
No public SSH access to any customer-hosting server. Administrative access goes through a private, key-only path limited to MFA-protected operator accounts.
-
You can restrict access to your controller to your own allowlisted IP addresses (plan dependent). A dedicated IP option is also available.
-
The customer portal and API are protected by a web application firewall and rate limiting.
Encryption
In transit:
-
Every customer hostname is served over HTTPS with an automatically issued and renewed TLS certificate. The customer portal and API are TLS protected end to end.
-
UniFi device-to-controller management traffic is protected by the inform protocol's built-in payload encryption.
At rest:
-
Nightly controller backups are encrypted and copied to multiple independent storage providers, including an immutable copy that cannot be changed or deleted for 30 days. This protects your backups from ransomware and from accidental loss.
-
We are rolling out full at-rest encryption (AES-256) of controller data across our server fleet. New server capacity comes online encrypted from day one, and existing servers are being converted on a rolling schedule.
Operations
-
The operating system is hardened, and security updates install automatically. Updates that need a restart happen in a weekly maintenance window.
-
Automated systems monitor health, traffic, and security events around the clock and alert our operations team.
-
Our codebase is scanned continuously for vulnerable dependencies and leaked secrets.
-
Every company account that controls infrastructure requires multi-factor authentication and uses least-privilege credentials.
-
Disaster recovery is documented and tested with quarterly fleet-wide restore drills. Our most recent drill recovered 100% of targets.
Your data
- You can secure portal sign-in with a passkey. Sign-in events are logged.
- You can download your controller backups at any time.
- If a subscription lapses, your data is archived so service can be restored if you come back.
Questions, or need the detailed Security Overview for a vendor review? Contact us on web chat or by support email.
Reporting a security issue
We welcome reports from security researchers and treat responsible disclosure as a partnership. If you believe you have found a vulnerability in a service we operate, please tell us before you tell anyone else, and give us a reasonable chance to fix it.
How to report: email security@cloudunifi.com (or support@cloudunifi.com) with the details. A clear description, the affected URL or endpoint, and the steps to reproduce (ideally a short proof of concept) help us validate and fix quickly. Our security contact is also published at cloudunifi.com/.well-known/security.txt.
What to expect: we aim to acknowledge your report within three business days, keep you updated as we investigate, and let you know when the issue is resolved. If you would like credit, we are glad to recognize you publicly once a valid issue is fixed.
Safe harbor
If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research. This means: only test against accounts and data you own, stop as soon as you have a proof of concept, never access, modify, or destroy customer data, and give us time to remediate before any public disclosure. Follow the rules below and we will treat your work as authorized.
In scope
The public web properties we operate, including cloudunifi.com, api.cloudunifi.com,
login.cloudunifi.com, portal.cloudunifi.com, auth.cloudunifi.com, and help.cloudunifi.com.
Out of scope
To keep everyone's time focused on issues that matter, the following are not eligible and are generally treated as informational or accepted risk:
-
Customer UniFi/UISP controllers and their contents. A customer's hosted controller, its configuration, and its data are not ours to authorize testing on. Do not attempt to access, enumerate, or test individual customer controllers.
-
Customer-owned custom domains pointed at our platform, and stale or parked DNS records that resolve to infrastructure we no longer operate (a third party may control that address).
-
Third-party platforms we build on (for example OVHcloud, Cloudflare, Stripe, and our authentication provider). Report those to the relevant vendor.
-
Denial of service, volumetric, brute-force, or load testing of any kind.
-
Social engineering or phishing of our staff, contractors, or customers, and physical attacks.
-
Automated scanner output without a working, demonstrated proof of concept.
-
Low-impact configuration findings with no demonstrated exploit, including: missing or misconfigured security headers, the HTTP
TRACE/TRACKmethods being enabled, HTTP method enumeration,TLS/cipher-suite grading opinions,SPF/DKIM/DMARC/DNSSECpolicy preferences, cookie flag nitpicks, clickjacking on pages with no sensitive actions, self-XSS, version or banner disclosure, and Cloudflare platform behavior such as/cdn-cgi/*endpoints.
Rewards
We do not run a paid bug bounty program. We recognize valid, impactful reports with public credit and, at our sole discretion, a token of appreciation. Any recognition is decided after we have validated the report, and is based on the real-world severity and impact of the issue. We cannot commit to a reward for a report we have not yet seen.