Security and Trust
Our security posture, the controls in operation, and what we do not yet do — stated precisely.
Our position on certifications
Nodexa does not hold, as of this date, ISO/IEC 27001 certification, a SOC 2 attestation, or any equivalent issued by an independent auditor. The controls described on this page are real and verifiable, but have not been subject to external audit.
We choose to state this openly. A badge we do not hold would protect no one's data, and the trust we aim to build depends on being precise about what we do and what we do not yet do.
Principles
Least privilege
Access granted is the minimum necessary for the role, for the time necessary.
Deny by default
What is not expressly permitted is denied.
Defense in depth
No single control is treated as sufficient on its own.
Secure by design
Security requirements are part of the design, not added afterwards.
Proportionality
Controls proportionate to risk and to organizational size, with limitations declared rather than concealed.
Verifiable transparency
We prefer to declare a limitation than to assert a control that does not hold up under verification.
Customer data sovereignty
The customer decides where their data is processed. The platform runs with self-hosted models, without dependence on any external provider.
Controls in operation
Centralized identity
Federated authentication through a single identity provider, with centralized revocation taking immediate effect across federated systems.
Isolation between organizations
Multi-tenant architecture separating data, knowledge bases and access policies per organization.
Role-based access control
Granular authorization by role, with privileged roles enumerable and subject to periodic review.
Unprivileged workloads
Containers run as non-root, with privilege escalation blocked, kernel capabilities dropped, seccomp profile applied and a read-only root filesystem.
Audit trail
Structured logging of tool execution with identity, organization, input, timestamps and outcome, alongside policy violation events.
Encryption in transit
Encrypted communication between client, platform and integrated services.
Point-in-time recovery
Database with recovery to a specific instant and retained daily backups, with deletion protection enabled.
Continuous scanning
Scanning for vulnerable dependencies, exposed secrets, infrastructure configuration and static analysis, on every code change and weekly.
Governance framework
Our security governance is formalized in a set of mandatory documents, periodically reviewed and kept under version control. The policy documents below are complemented by a verified technical baseline, a remediation plan with deadlines, and our record of answers given to customer security assessments — all available under a confidentiality agreement.
Information Security Policy
Principles, roles, information classification, exceptions and sanctions
Access Deprovisioning and Review
Access lifecycle, offboarding and privileged account review
Vulnerability Management
Scanning, patch management, finding triage and zero-day response
Incident Response
Detection, containment, communication and post-incident analysis
Third Party and Subprocessor Management
Supplier inventory and incidents originating with third parties
Continuity and Disaster Recovery
Recovery capabilities, RPO and RTO objectives and testing regime
Awareness and Training
Timing, minimum content and participation records
Full documentation
The complete documents, including operational procedures and inventories, are made available to customers and assessors under a confidentiality agreement.
Request accessThird parties and subprocessors
We maintain an inventory of the third parties that make up or support our operation, classified by the access they hold to data. The named inventory is part of the documentation made available under a confidentiality agreement.
Infrastructure
Cloud providers hosting compute, managed database, object storage and key management.
Language models — optional connectors
Model providers process no data until configured by the customer. The platform supports self-hosted models, allowing operation without any external provider. Where the customer defines a fallback provider for unavailability, assessing its jurisdictional suitability is the customer's responsibility.
Channels — optional connectors
Messaging and identity integrations activated at the customer's decision, processing the data inherent to the chosen channel.
Responsible disclosure
If you have identified a vulnerability in our services, write to the address below. We acknowledge receipt within 2 business days. Researchers who report in good faith and without degrading service for others will not face legal action from Nodexa.
security@nodexa.com.br