Compliance

LGPD & Security

Our commitment to data protection and regulatory compliance

LGPD

Brazilian Data Protection

GDPR

European Regulation

Zero-Trust Runtime

Non-root, least-privilege containers

Tenant Isolation

RBAC and multi-tenant separation

LGPD Compliance

Nodexa is built to support your LGPD obligations. We act as operator (operador) under the LGPD, and our platform, contracts, and controls are designed so that your organization can meet its duties as controller.

Data Subject Rights

Full support for access, correction, deletion, and portability requests

Consent Management

Granular consent tracking and management capabilities

Data Processing Records

Comprehensive logging of all data processing activities

Breach Notification

Defined breach notification procedure with documented roles, timelines, and regulator contact path

Security Measures

We implement comprehensive security measures to protect your data at every level.

Infrastructure Security

  • On-premise or sovereign cloud deployment options
  • Private networking with network policy enforcement between workloads
  • Pod-level hardening: seccomp profiles, dropped capabilities, read-only root filesystem

Data Protection

  • AES-256 encryption at rest
  • TLS 1.3 encryption in transit
  • Customer-managed encryption keys available

Access Control

  • Role-based access control (RBAC)
  • Multi-factor authentication support via Keycloak
  • Single sign-on (SSO) via Keycloak

Data Processing Agreement

We offer comprehensive Data Processing Agreements (DPAs) that clearly define the responsibilities of both parties in relation to personal data processing. Our DPA covers:

  • Subject matter, duration, and purpose of processing
  • Types of personal data and categories of data subjects
  • Obligations and rights of the controller
  • Security measures and sub-processor management
  • Data breach notification procedures

Incident Response

In the unlikely event of a security incident, our dedicated team follows a strict protocol:

< 1hTriage and severity assessment (from time of awareness)
< 4hContainment and mitigation
< 24hCustomer notification
< 72hRegulatory notification (if required)