Trust Center

Trust is the foundation of everything we do

Here you'll find all the principles, certifications, policies, and compliance evidence that underpin the Defender360 platform.

Principles

The four pillars that guide our security

Every technical decision at Defender360 is evaluated against these 4 principles.

Confidentiality

Each customer's data is fully separated from all others — isolated at the database level. Everything encrypted in transit (TLS 1.3) and at rest (AES-256).

Integrity

Immutable history of all sensitive operations. Every change is versioned and cryptographically verified.

Availability

Multi-zone AWS architecture with continuous replication. 99.9% uptime (monthly average) and 24x7 monitoring.

Privacy

LGPD compliance from day one. You own your data — data portability and deletion rights are guaranteed.

Certifications

Standards we follow to protect you

We operate in alignment with the leading security and privacy frameworks in the industry.

ISO/IEC 27001

In progress

Information Security Management aligned to ISO 27001:2022 controls.

SOC 2 Type II

In progress

Security, availability, and confidentiality controls audited annually by third parties.

LGPD

Compliant

Brazilian General Data Protection Law (Lei 13.709/2018). A designated DPO and documented processes are in place.

BCB 538

Compliant

Banco Central Resolution BCB 538. Backup control, digital certificate monitoring, and production change traceability — all integrated into the ITSM.

GDPR

Ready

Framework prepared for customers with European operations, with the eu-central-1 region available.

Brazil Compliance

Built for Brazilian regulation

We were born in Brazil and serve regulated businesses. Regulatory controls are part of the product — not an add-on.

LGPD — Personal Data Protection

  • Designated Data Protection Officer (DPO) with a direct channel at [email protected]
  • Rights of access, correction, portability, and deletion guaranteed to data subjects
  • Processing activity records and documented legal basis for each purpose
  • Configurable retention policy per organization and permanent deletion on demand

BCB 538 — Central Bank Resolution

  • Automated backup verification for critical systems integrated into the asset inventory
  • Digital certificate monitoring with early expiration alerts
  • Full production change traceability with an approval workflow (CAB)
  • Reports ready for internal audits and external regulatory bodies
Policies

How we operate securely every day

Documented policies, communicated internally and enforced throughout the entire development lifecycle.

Access Control

Two-factor authentication required for all employees. Role-based permissions, least-privilege principle, and quarterly access reviews.

Data Handling

Data classification, end-to-end encryption, per-organization database isolation, and continuous auditing.

Incident Response

Documented runbook, 24x7 on-call team, and proactive communication to affected customers within the regulatory timeframe.

Secure Development

Mandatory code reviews, automated security analysis (covering code, dependencies, and the running application), dependency management, and OWASP training for the team.

Vendor Management

Risk assessment for every vendor that processes data. Contracts include LGPD clauses and signed data processing agreements.

Business Continuity

Tested continuity plan with an RPO of 1h and RTO of 4h. Off-site backups and documented recovery drills.

Want a deeper look at our security posture?

We provide the security questionnaire, full policy documentation, and technical architecture under NDA for enterprise customers.