Security and Compliance
Infrastructure built
for compliance.
Privacy by default, end-to-end encryption and a declared legal basis from the first endpoint, not added later.
Pillars
Four layers of protection.
LGPD (Law 13.709/2018, Brazil's data protection law)
- Declared legal basis for each data processing activity
- Specific purpose and data minimization
- Data protection impact assessment (RIPD) available to enterprise customers
- Designated and accessible data protection officer (DPO)
- Documented data retention and deletion policy
100% Brazilian infrastructure
- Data processed and stored exclusively in Brazil
- No international transfer of personal data
- Compliance with the territorial requirements of the ANPD (Brazil's data protection authority)
- Geographic redundancy across Brazilian regions
- Per-customer environment isolation on enterprise plans
Encryption and access
- TLS 1.3 on all data in transit
- AES-256 for data at rest
- API keys with least-privilege scope
- Periodic rotation of internal credentials
- Audit logs available to enterprise customers
Security practices
- Controls aligned with SOC 2 and ISO 27001 guidelines
- Vulnerability management with a remediation cycle
- Security tests run periodically
- Responsible disclosure policy
- Auditable architecture available for due diligence
Incident management
Ready for the unexpected.
Continuous detection
24/7 monitoring with automated alerts for anomalous access and usage patterns.
Structured response
Internal incident response process with defined roles and a documented containment SLA.
Transparent notification
Affected customers are notified within the legal deadline, with a detailed report of what happened.
For your DPO
Documentation available.
Enterprise customers get full technical documentation for due diligence and internal audits.
Compliance included.
From the first call.
Start using the API and get LGPD, encryption and a legal basis covered by default.