Transport and browser
HTTPS with HSTS, content policy, frame blocking, content-type protection, and restrictive permissions policies.
This center contains only protections implemented and information published in the current project. Certifications, external audits, or compliance levels are not declared without a validated record.
The controls below are verifiable in the project's code and automated tests.
HTTPS with HSTS, content policy, frame blocking, content-type protection, and restrictive permissions policies.
Form submissions and audience collection reject requests without a valid origin or from another domain.
Access uses authenticated identity and permissions separated by module and operation type.
Relevant administrative actions are logged, sensitive deletions require reinforced confirmation, and operational records use soft deletion where provided.
First-party collection depends on consent and does not store IP addresses, typed text, or form content.
The build checks routes, migrations, request origin, security headers, metadata, and error behavior.
This page does not replace an independent audit report and does not assign controls that have not been evidenced.
Good-faith reports should allow safe reproduction without exposing personal data, disrupting services, or increasing the identified impact.
Provide the affected route, observed behavior, possible impact, and minimum reproduction steps.
Do not include credentials, résumés, contacts, personal data, or information obtained from third parties.
Use Talk to our team, select Cloud, DevOps, and Security, then choose Security and compliance.
The record will be reviewed and routed internally. No public response time is guaranteed in this version.
The set below centralizes institutional information, public policies, and operational evidence available in the current project.
Legal name, Brazilian company ID, address, structure, and published representatives.
Open materialPurposes, legal bases, retention, rights, and channels related to personal data.
Open materialNavigation, contrast, language, and text adjustment resources available on the site.
Open materialConditions applicable to public pages, content, and features.
Open materialLeadership and service profiles available under explicit validation criteria.
Open materialImplemented controls, statement boundaries, and the vulnerability process.
Open materialPartners, certifications, and external evidence will remain outside these materials until their records are approved.