Updated June 10, 2026
Security
Untitled UI takes security, privacy, and access control seriously.
Untitled UI is primarily delivered as downloadable source code and design assets. We do not process or store customer production application data, payment card information, healthcare records, or other highly sensitive end-user data.
Download our Security Pack for a more detailed overview of how Untitled UI approaches security, privacy, and data protection.
Infrastructure & Hosting
Untitled UI uses trusted managed infrastructure providers for hosting, authentication, database management, CDN delivery, and operational services.
All traffic is encrypted in transit using HTTPS/TLS.
Our infrastructure providers include:
Authentication & Access Control
Untitled UI uses passwordless authentication via secure magic-link login flows.
- No customer passwords are stored by Untitled UI
- Authentication tokens are single-use
- Access to production systems is restricted to authorized personnel only
- Multi-factor authentication (MFA) is enabled across infrastructure providers and internal administrative accounts
Enterprise customers can enable:
- SAML 2.0 Single Sign-On (SSO)
- SCIM 2.0 automated user provisioning and de-provisioning
- Domain verification for organization access control
When SSO is enabled for a verified domain, authentication is managed through the customer’s identity provider.
Repository Access
Enterprise customers may receive access to private GitHub repositories containing Untitled UI React source code.
Repository access is:
- Restricted to authorized users
- Managed through GitHub access controls
- Revocable at any time
- Governed by the applicable license agreement
Audit Logging
Enterprise organizations include access to identity and access audit logs.
Audit events may include:
- SSO authentication events
- SCIM provisioning and de-provisioning
- Team membership changes
- API key creation and revocation
- GitHub access changes
Organization administrators can export audit logs from their account dashboard.
Customer Data
Untitled UI stores limited account and licensing information required for access control, billing, and product delivery.
Stored information may include:
- Account and team-member email addresses
- License and order information
- Team membership and access status
- GitHub usernames (when repository access is enabled)
- Identity-provider metadata for Enterprise SSO organizations
- Audit log events
Untitled UI does not store:
- Payment card information
- Banking information
- Customer production application data
- End-user data belonging to customer applications
Payment processing is handled by Polar.sh as Merchant of Record.
AI Features
Untitled UI offers optional semantic component search functionality.
When used, search query text may be processed by Google’s Generative AI embedding services solely for semantic matching purposes. No customer application data or stored personal data is sent to these services.
Compliance
Untitled UI is not currently certified under SOC 2, ISO 27001, or similar compliance frameworks.
Additional security documentation may be available to Enterprise customers upon request.
Security Reporting
Security concerns or vulnerability reports may be submitted to [email protected].
We request responsible disclosure of any identified vulnerabilities.
Legal & Privacy
Additional information is available in our:
- Data Processing Addendum (DPA);
- Privacy Policy;
- License Agreement;
- Enterprise User License Agreement (EULA);
- Subprocessors page; and
- Related legal documentation.
Untitled UI
Untitled UI® (ABN 65 655 466 729) is operated by Sisyphus Ventures Pty Ltd (ACN 655 466 729), based in Melbourne, Australia.
If you have any questions regarding this Security page or Untitled UI’s privacy and data protection practices, please get in touch with our friendly team via [email protected].
Download Security Pack
Download our Security Pack for a more detailed overview of how Untitled UI approaches security, privacy, and data protection:
Join our affiliate program





























