Trust Center

Security and Trust

Our security posture, the controls in operation, and what we do not yet do — stated precisely.

Our position on certifications

Nodexa does not hold, as of this date, ISO/IEC 27001 certification, a SOC 2 attestation, or any equivalent issued by an independent auditor. The controls described on this page are real and verifiable, but have not been subject to external audit.

We choose to state this openly. A badge we do not hold would protect no one's data, and the trust we aim to build depends on being precise about what we do and what we do not yet do.

Principles

Least privilege

Access granted is the minimum necessary for the role, for the time necessary.

Deny by default

What is not expressly permitted is denied.

Defense in depth

No single control is treated as sufficient on its own.

Secure by design

Security requirements are part of the design, not added afterwards.

Proportionality

Controls proportionate to risk and to organizational size, with limitations declared rather than concealed.

Verifiable transparency

We prefer to declare a limitation than to assert a control that does not hold up under verification.

Customer data sovereignty

The customer decides where their data is processed. The platform runs with self-hosted models, without dependence on any external provider.

Controls in operation

Centralized identity

Federated authentication through a single identity provider, with centralized revocation taking immediate effect across federated systems.

Isolation between organizations

Multi-tenant architecture separating data, knowledge bases and access policies per organization.

Role-based access control

Granular authorization by role, with privileged roles enumerable and subject to periodic review.

Unprivileged workloads

Containers run as non-root, with privilege escalation blocked, kernel capabilities dropped, seccomp profile applied and a read-only root filesystem.

Audit trail

Structured logging of tool execution with identity, organization, input, timestamps and outcome, alongside policy violation events.

Encryption in transit

Encrypted communication between client, platform and integrated services.

Point-in-time recovery

Database with recovery to a specific instant and retained daily backups, with deletion protection enabled.

Continuous scanning

Scanning for vulnerable dependencies, exposed secrets, infrastructure configuration and static analysis, on every code change and weekly.

Governance framework

Our security governance is formalized in a set of mandatory documents, periodically reviewed and kept under version control. The policy documents below are complemented by a verified technical baseline, a remediation plan with deadlines, and our record of answers given to customer security assessments — all available under a confidentiality agreement.

NDX-SEC-001

Information Security Policy

Principles, roles, information classification, exceptions and sanctions

NDX-SEC-002

Access Deprovisioning and Review

Access lifecycle, offboarding and privileged account review

NDX-SEC-003

Vulnerability Management

Scanning, patch management, finding triage and zero-day response

NDX-SEC-004

Incident Response

Detection, containment, communication and post-incident analysis

NDX-SEC-005

Third Party and Subprocessor Management

Supplier inventory and incidents originating with third parties

NDX-SEC-006

Continuity and Disaster Recovery

Recovery capabilities, RPO and RTO objectives and testing regime

NDX-SEC-007

Awareness and Training

Timing, minimum content and participation records

Full documentation

The complete documents, including operational procedures and inventories, are made available to customers and assessors under a confidentiality agreement.

Request access

Third parties and subprocessors

We maintain an inventory of the third parties that make up or support our operation, classified by the access they hold to data. The named inventory is part of the documentation made available under a confidentiality agreement.

Infrastructure

Cloud providers hosting compute, managed database, object storage and key management.

Language models — optional connectors

Model providers process no data until configured by the customer. The platform supports self-hosted models, allowing operation without any external provider. Where the customer defines a fallback provider for unavailability, assessing its jurisdictional suitability is the customer's responsibility.

Channels — optional connectors

Messaging and identity integrations activated at the customer's decision, processing the data inherent to the chosen channel.

Responsible disclosure

If you have identified a vulnerability in our services, write to the address below. We acknowledge receipt within 2 business days. Researchers who report in good faith and without degrading service for others will not face legal action from Nodexa.

security@nodexa.com.br

Related documents: LGPD · Privacy · AI Ethics