Documented security

Clear controls for trusted digital relationships.

This center contains only protections implemented and information published in the current project. Certifications, external audits, or compliance levels are not declared without a validated record.

Implemented controls

Protections applied to the site and administration.

The controls below are verifiable in the project's code and automated tests.

01

Transport and browser

HTTPS with HSTS, content policy, frame blocking, content-type protection, and restrictive permissions policies.

02

Public submissions

Form submissions and audience collection reject requests without a valid origin or from another domain.

03

Administrative area

Access uses authenticated identity and permissions separated by module and operation type.

04

Data and audit

Relevant administrative actions are logged, sensitive deletions require reinforced confirmation, and operational records use soft deletion where provided.

05

Consent-based metrics

First-party collection depends on consent and does not store IP addresses, typed text, or form content.

06

Continuous validation

The build checks routes, migrations, request origin, security headers, metadata, and error behavior.

Limits of this statement

This page does not replace an independent audit report and does not assign controls that have not been evidenced.

Vulnerability disclosure

A responsible channel for reporting issues.

Good-faith reports should allow safe reproduction without exposing personal data, disrupting services, or increasing the identified impact.

01

Describe

Provide the affected route, observed behavior, possible impact, and minimum reproduction steps.

02

Protect

Do not include credentials, résumés, contacts, personal data, or information obtained from third parties.

03

Submit

Use Talk to our team, select Cloud, DevOps, and Security, then choose Security and compliance.

04

Wait for triage

The record will be reviewed and routed internally. No public response time is guaranteed in this version.

Good-faith research

  • Do not interrupt, degrade, or overload the service.
  • Do not access, modify, copy, or delete other people's data.
  • Do not use social engineering, phishing, or attempts against third parties.
  • Stop testing when exposure risk or operational impact is identified.
Report a vulnerability
Due diligence materials

Documents organized for review.

The set below centralizes institutional information, public policies, and operational evidence available in the current project.

01

Institutional information

Legal name, Brazilian company ID, address, structure, and published representatives.

Open material
02

Privacy and cookies

Purposes, legal bases, retention, rights, and channels related to personal data.

Open material
03

Accessibility

Navigation, contrast, language, and text adjustment resources available on the site.

Open material
04

Terms of use

Conditions applicable to public pages, content, and features.

Open material
05

Published credentials

Leadership and service profiles available under explicit validation criteria.

Open material
06

Security policy

Implemented controls, statement boundaries, and the vulnerability process.

Open material
Documentation status

Publication without unsupported claims.

Partners, certifications, and external evidence will remain outside these materials until their records are approved.