Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Next revision
Previous revision
pub:company:service_strategy [21.07.2026 13:28] – Service Strategy and Commitments - What Unicis delivers Predrag Tasevskipub:company:service_strategy [21.07.2026 14:00] (current) – Update tech stack: Jitsi and LimeSurvey are self-hosted; GitLab EU for code Predrag Tasevski
Line 35: Line 35:
   * ❌ Your data classification or privacy decisions — that's your choice   * ❌ Your data classification or privacy decisions — that's your choice
   * ❌ Your compliance obligations — we provide tools; you define your scope   * ❌ Your compliance obligations — we provide tools; you define your scope
-  * ❌ Third-party platforms (AWS, Mautic, Dolibarr, GitHub, etc.) — vendors manage their security+  * ❌ Third-party platforms (Mautic, Dolibarr, Nextcloud, etc.) — vendors manage their security
   * ❌ Your internal access control — you decide who in your org uses Unicis   * ❌ Your internal access control — you decide who in your org uses Unicis
  
 ====== Our Service Commitments ====== ====== Our Service Commitments ======
  
-As an ISO 20000-1 provider, Unicis commits to these measurable targets:+As an [[pub:trust_center:iso_20000_1_overview|ISO 20000-1]] provider, Unicis commits to these measurable targets:
  
-^ Service Level Indicator ^ Target ^ How We Track It ^ +^ Service Level Indicator ^ Target ^ How We Track It ^ Link 
-| **Platform Availability** | ≥ 99% uptime per month | [[https://status.unicis.tech|Status Page]] / Grafana monitoring | +| **Platform Availability** | ≥ 99% uptime per month | [[https://status.unicis.tech|Status Page]] / Grafana monitoring | [[pub:company:scorecard|Scorecard #6]] 
-| **Critical Incident Response (P1)** | ≤ 2 hours to respond | Incident response log | +| **Critical Incident Response (P1)** | ≤ 2 hours to respond | Incident response log | [[pub:company:scorecard|Scorecard #11]] 
-| **High Priority Response (P2)** | ≤ 8 hours to respond | Incident response log | +| **High Priority Response (P2)** | ≤ 8 hours to respond | Incident response log | [[pub:company:scorecard|Scorecard]] 
-| **Deployment Success Rate** | ≥ 99% (no production bugs) | GitHub Actions, incident log | +| **Deployment Success Rate** | ≥ 99% (no production bugs) | GitHub Actions, incident log | [[pub:company:scorecard|Scorecard #14]] 
-| **Security Patch Deployment** | ≤ 7 days for critical vulnerabilities | Vulnerability tracking | +| **Security Patch Deployment** | ≤ 7 days for critical vulnerabilities | Vulnerability tracking | [[pub:company:scorecard|Scorecard #12]] 
-| **Mean Time to Recovery (MTTR)** | ≤ 4 hours for critical incidents | Incident recovery log |+| **Mean Time to Recovery (MTTR)** | ≤ 4 hours for critical incidents | Incident recovery log | [[pub:trust_center:iso_20000_1_overview|ISO 20000-1]] |
  
 Real-time performance is visible on our [[pub:company:scorecard|Scorecard]]. Real-time performance is visible on our [[pub:company:scorecard|Scorecard]].
Line 54: Line 54:
 ====== How We Operate ====== ====== How We Operate ======
  
-Our service delivery follows **ITIL best practices** (ISO 20000-1 requirement):+Our service delivery follows **ITIL best practices** ([[pub:trust_center:iso_20000_1_overview|ISO 20000-1 requirement]]):
  
 === Service Design === === Service Design ===
Line 62: Line 62:
   * Scalable (handles growth)   * Scalable (handles growth)
   * Maintainable (clear code, documentation)   * Maintainable (clear code, documentation)
 +
 +For details, see [[pub:trust_center:iso_20000_1_overview|ISO 20000-1 Overview]].
  
 === Service Transition === === Service Transition ===
Line 78: Line 80:
   * Backups and disaster recovery   * Backups and disaster recovery
   * Access control (who can do what)   * Access control (who can do what)
 +
 +For details, see [[pub:trust_center:iso_27001_overview|ISO 27001 Overview]] (security) and [[pub:trust_center:isms_policy|Information Security Policy]].
  
 === Continuous Improvement === === Continuous Improvement ===
 We improve based on: We improve based on:
-  * Metrics (uptime %, response time, deployment success)+  * Metrics (uptime %, response time, deployment success) — tracked in [[pub:company:scorecard|Scorecard]]
   * Customer feedback   * Customer feedback
   * Incident investigations (what went wrong? how to prevent?)   * Incident investigations (what went wrong? how to prevent?)
-  * Security audits (annual third-party review)+  * Security audits (annual third-party review per [[pub:trust_center:iso_27001_overview|ISO 27001]])
  
 ====== Service Customers ====== ====== Service Customers ======
Line 91: Line 95:
   * EU SMEs (10–100 employees)   * EU SMEs (10–100 employees)
   * Operating in regulated industries   * Operating in regulated industries
-  * Navigating NIS2, GDPR, DORA, CRA, ISO 27001+  * Navigating [[pub:trust_center:nis2_scope_determination|NIS2]][[pub:trust_center:cra_scope_determination|CRA]], [[pub:trust_center:policies:privacy_policy|GDPR]], DORA, ISO 27001
   * Seeking professional compliance software (not DIY spreadsheets)   * Seeking professional compliance software (not DIY spreadsheets)
  
Line 111: Line 115:
 | **Security Question** | [[mailto:security@unicis.tech|security@unicis.tech]] | 2 hours | | **Security Question** | [[mailto:security@unicis.tech|security@unicis.tech]] | 2 hours |
  
-====== Service Dependencies ======+====== Infrastructure & Service Dependencies ======
  
-Unicis relies on trusted vendors for infrastructure and services:+**Unicis Platform Hosting:** 
 +  * **Primary Infrastructure** — Scaleway VPS in Amsterdam (EU only) 
 +  * **AI Endpoint & DNS** — OVH (AI processing and domain management) 
 +  * Additional EU regions available on request
  
-  * **AWS / Hetzner** — Cloud infrastructure (servers, storage, redundancy+**Self-Hosted Services (On Scaleway):** 
-  * **Mautic** — Email marketing lead nurture +  * Mautic — Email marketing and lead nurture (deprecated soon) 
-  * **Dolibarr** — ERP/CRM system +  * Dolibarr — ERP/CRM system for accounts and subscriptions 
-  * **GitHub** — Code repository +  * Nextcloud — Document storage and collaboration 
-  * **Jitsi** — Video conferencing+  OpenProject — Project management and budget tracking 
 +  Moodle — Training and learning management 
 +  FreeScout — Support ticket management 
 +  Jitsi — Video conferencing for 15+ participants 
 +  * LimeSurvey — Surveys, polls, feedback collection 
 +  Element/Matrix — Internal team communication 
 +  n8n — Workflow automation and integrations 
 +  Matomo — Analytics and usage metrics 
 +  Fider — Feedback and feature roadmap
  
-All vendors are assessed for security and reliability. See [[pub:trust_center:subprocessors|Trusted Subprocessors]] for vendor details and contracts.+**Code Repository:** 
 +  * **GitLab EU** — Proprietary code repository and CI/CD pipeline (EU-based) 
 + 
 +**Third-Party Cloud Services:** 
 +  * Wise — Payment processing and transfers 
 +  * Discord — Community and partner communication 
 + 
 +**Data Location:** 
 +  * Primary services hosted in **Amsterdam, EU (Scaleway)** 
 +  * All customer data remains in EU jurisdiction 
 +  * Compliant with GDPR, NIS2, and CRA data residency requirements 
 +  * Code stored in EU-based GitLab 
 + 
 +All vendors are assessed for security and reliability. See [[pub:trust_center:subprocessors|Trusted Subprocessors]] for vendor details and contracts. For detailed infrastructure information, see [[pub:trust_center:infrastructure_and_tech_stack|Infrastructure & Tech Stack]]. 
 + 
 +====== Risk Management ====== 
 + 
 +We systematically identify and manage risks to your data and platform availability. See [[pub:trust_center:risk_framework|Risk Assessment Framework]] for details on our approach.
  
 ====== Approved Service Changes ====== ====== Approved Service Changes ======
Line 130: Line 162:
   * Updated on this page (with date and change details)   * Updated on this page (with date and change details)
  
-Last significant change: **N/A (first version)**+Last significant change: **N/A (first version, October 2026)** 
 + 
 +====== Standards & Certifications ====== 
 + 
 +  * [[pub:trust_center:iso_20000_1_overview|ISO 20000-1:2018]] — IT Service Management (certification in progress) 
 +  * [[pub:trust_center:iso_27001_overview|ISO 27001:2022]] — Information Security Management (certification in progress) 
 +  * [[pub:trust_center:nis2_scope_determination|NIS2 Directive]] — EU cybersecurity requirements 
 +  * [[pub:trust_center:cra_scope_determination|CRA Scope]] — EU cyber resilience requirements 
 +  * [[pub:trust_center:policies:privacy_policy|GDPR]] — EU data protection
  
 ====== Related ====== ====== Related ======
  
-  * [[pub:trust_center:iso_20000_1_overview|ISO 20000-1:2018 Certification]]+  * [[pub:trust_center:iso_20000_1_overview|ISO 20000-1:2018 Certification]] — Service Management System 
 +  * [[pub:trust_center:iso_27001_overview|ISO 27001:2022 Certification]] — Information Security Management
   * [[pub:company:scorecard|Service Performance Scorecard]] — Real-time metrics   * [[pub:company:scorecard|Service Performance Scorecard]] — Real-time metrics
-  * [[pub:trust_center:subprocessors|Trusted Subprocessors]] +  * [[pub:trust_center:isms_policy|Information Security Policy]] — Security commitment 
-  * [[pub:company:traction#level_10_meeting|How We Review Performance]]+  * [[pub:trust_center:risk_framework|Risk Assessment Framework]] — How we manage risks 
 +  * [[pub:trust_center:subprocessors|Trusted Subprocessors]] — Vendor details 
 +  * [[pub:trust_center:infrastructure_and_tech_stack|Infrastructure & Tech Stack]] — Where your data lives 
 +  * [[pub:company:accountability_chart|Accountability Chart]] — Leadership roles 
 +  * [[pub:company:traction|Quarterly Planning & Reviews]] — How we review performance
  
 ====== Questions? ====== ====== Questions? ======
Line 144: Line 189:
  
 → Email us: **support@unicis.tech** → Email us: **support@unicis.tech**
 +
 +----
 +
 +==== Navigation ====
 +
 +← [[pub:trust_center|Trust Center]] | [[pub:company:scorecard|Scorecard →]]
  
 ---- ----