Security at CloudUnifi

Customers trust us with the configuration of their networks. This page summarizes how we protect the service and your data. A detailed Security Overview document for vendor security reviews (CIS, ISO 27001 supplier assessments, and similar) is available to customers on request via support.

Hosting and data centers

Your UniFi controller runs on dedicated servers operated by our datacenter partner, OVHcloud, in Australia, Canada, France, Germany, the UK, and the US. OVHcloud provides physical security, power, and environmental controls for these facilities, and holds certifications including ISO/IEC 27001, ISO/IEC 27017, and ISO/IEC 27018 covering the data centers and dedicated-server services we use. Every customer controller runs in its own isolated container — customers never share an application process or data store.

Network protection

  • Always-on DDoS mitigation and an edge network firewall in front of every server.

  • Host firewalls are default-deny: only the ports the UniFi service requires are open.

  • No public SSH access to any customer-hosting server — administrative access uses a private, key-only path limited to MFA-protected operator accounts.

  • Optional restriction of your controller to your own allowlisted IP addresses (plan-dependent), and a dedicated IP option.

  • The customer portal and API are protected by a web application firewall and rate limiting.

Encryption

  • Every customer hostname is served over HTTPS with an automatically issued and renewed TLS certificate.

  • Nightly controller backups are encrypted and replicated to multiple independent storage providers, including an immutable copy that cannot be altered or deleted for 30 days — protection against ransomware and accidental loss.

Operations

  • The operating system is hardened and security updates are applied on an automated cadence, with scheduled weekly maintenance windows.

  • Automated systems monitor health, traffic, and security events 24/7 and alert our operations team.

  • Our codebase is continuously scanned for vulnerable dependencies and leaked secrets.

  • All company accounts controlling infrastructure require multi-factor authentication, with least-privilege access credentials.

  • Disaster recovery is documented and exercised — our July 2026 fleet-wide restore drill recovered 100% of targets.

Your data

  • Portal sign-in is passkey-first (phishing-resistant), with password fallback, and sign-in events are audit-logged.

  • Controller backups can be downloaded by you at any time.

  • If a subscription lapses, data is archived so service can be restored if you return.

Questions, or need the detailed Security Overview for a vendor review? Contact us via web chat or support email.