Legal
Security
How we protect systems and data, and how to report a problem.
Last updated
How we build
Least privilege by default, secrets in a managed store rather than in code or environment files committed to a repository, dependencies monitored for known vulnerabilities, and every change reviewed before it reaches production.
Client systems
We work in client-owned infrastructure with access scoped to what the engagement needs, and that access is revoked when it ends. Where data cannot leave a client’s environment, the system is designed to run inside it.
Agent access
Agents on a desk get access to the systems their queue requires and no more. Access is logged, reviewed, and removed when someone leaves the account.
AI systems specifically
Scoped permissions per agent, typed tool contracts so malformed calls fail at the boundary, human approval gates on consequential actions, hard step and spend ceilings, and a full replayable trace of every action taken. Client data is not used to train models.
Reporting a vulnerability
Email admin@universalvirtualsupport.com with SECURITY in the subject line and enough detail to reproduce it. We will acknowledge within two business days and keep you updated until it is resolved. We will not pursue anyone who reports a genuine issue in good faith and does not access or destroy data in the process.
Questions about this page? Email admin@universalvirtualsupport.com.