Trust is the foundation of everything we do
Here you'll find all the principles, certifications, policies, and compliance evidence that underpin the Defender360 platform.
The four pillars that guide our security
Every technical decision at Defender360 is evaluated against these 4 principles.
Confidentiality
Each customer's data is fully separated from all others — isolated at the database level. Everything encrypted in transit (TLS 1.3) and at rest (AES-256).
Integrity
Immutable history of all sensitive operations. Every change is versioned and cryptographically verified.
Availability
Multi-zone AWS architecture with continuous replication. 99.9% uptime (monthly average) and 24x7 monitoring.
Privacy
LGPD compliance from day one. You own your data — data portability and deletion rights are guaranteed.
Standards we follow to protect you
We operate in alignment with the leading security and privacy frameworks in the industry.
ISO/IEC 27001
In progressInformation Security Management aligned to ISO 27001:2022 controls.
SOC 2 Type II
In progressSecurity, availability, and confidentiality controls audited annually by third parties.
LGPD
CompliantBrazilian General Data Protection Law (Lei 13.709/2018). A designated DPO and documented processes are in place.
BCB 538
CompliantBanco Central Resolution BCB 538. Backup control, digital certificate monitoring, and production change traceability — all integrated into the ITSM.
GDPR
ReadyFramework prepared for customers with European operations, with the eu-central-1 region available.
Built for Brazilian regulation
We were born in Brazil and serve regulated businesses. Regulatory controls are part of the product — not an add-on.
LGPD — Personal Data Protection
- Designated Data Protection Officer (DPO) with a direct channel at [email protected]
- Rights of access, correction, portability, and deletion guaranteed to data subjects
- Processing activity records and documented legal basis for each purpose
- Configurable retention policy per organization and permanent deletion on demand
BCB 538 — Central Bank Resolution
- Automated backup verification for critical systems integrated into the asset inventory
- Digital certificate monitoring with early expiration alerts
- Full production change traceability with an approval workflow (CAB)
- Reports ready for internal audits and external regulatory bodies
How we operate securely every day
Documented policies, communicated internally and enforced throughout the entire development lifecycle.
Access Control
Two-factor authentication required for all employees. Role-based permissions, least-privilege principle, and quarterly access reviews.
Data Handling
Data classification, end-to-end encryption, per-organization database isolation, and continuous auditing.
Incident Response
Documented runbook, 24x7 on-call team, and proactive communication to affected customers within the regulatory timeframe.
Secure Development
Mandatory code reviews, automated security analysis (covering code, dependencies, and the running application), dependency management, and OWASP training for the team.
Vendor Management
Risk assessment for every vendor that processes data. Contracts include LGPD clauses and signed data processing agreements.
Business Continuity
Tested continuity plan with an RPO of 1h and RTO of 4h. Off-site backups and documented recovery drills.
Want a deeper look at our security posture?
We provide the security questionnaire, full policy documentation, and technical architecture under NDA for enterprise customers.