Ultra PRO Trust Center edisupport@ultrapro.com

Privacy & trust center

Trust starts with verified evidence.

This independent Trust Center explains Ultra PRO's control approach and provides a controlled library for approved certifications, audits, privacy materials, and due-diligence evidence.

Evidence policy Only approved and verified materials are published. A regulation or framework is not labeled as a certification without supporting evidence.

Principles

Partner data is handled according to purpose and risk.

Ultra PRO minimizes data according to purpose, uses approved encrypted transport, separates non-production and production activity, limits access, and preserves operational evidence appropriate to risk.

  • Do not send passwords, API tokens, private keys, certificates, or production payloads by ordinary email.
  • Use non-production data for development and testing unless an approved exception is documented.
  • Keep credentials and secrets outside source code and static website assets.
  • Assign a business owner and an exception owner for each material flow.
  • Document cutover, rollback, recovery, and hypercare before production enablement.

Control areas

Controls applied according to purpose and risk.

Identity and access

Role-based access, least privilege, environment separation, named ownership, and controlled production access are applied to partner connectivity and business systems.

Encryption and secret management

Approved encrypted transport is selected during discovery. Deployment credentials use federated identity where possible. Runtime secrets belong in an approved secret store such as Azure Key Vault, not GitHub source or client-side JavaScript.

Monitoring and traceability

Transactions are monitored through acknowledgments, logs, alerts, correlation identifiers, counts, and reconciliation appropriate to the lane. Operational evidence supports incident analysis and recovery.

Secure delivery lifecycle

Mapping review, negative testing, partner certification, business UAT, change approval, rollback planning, and hypercare form the production release gate.

Data lifecycle

Retention, archive, quarantine, and deletion needs are defined according to the data, partner agreement, operating requirement, and applicable policy.

Document library

Approved evidence and controlled requests.

Publicly approved files display a Download action. Confidential evidence remains request-only and may require validation, an NDA, or delivery through an approved secure channel.

Request process

How to request due-diligence materials.

  1. Email edisupport@ultrapro.com with your company, role, business purpose, requested material, and related business relationship or project.
  2. Ultra PRO validates the request, document ownership, current availability, and distribution restrictions.
  3. If required, the parties complete an NDA or approved access step.
  4. Approved materials are delivered through an appropriate secure channel with any use or retention limitations.

Security reporting

Report a security concern.

Contact edisupport@ultrapro.com with a concise description and a safe callback method. Do not include live credentials, exploit code, sensitive payloads, or personal data in the initial message. Ultra PRO will establish a secure follow-up channel when needed.