Version 1.2 · Effective 3 September 2026 · Next review 3 September 2027
Download as PDF · Privacy Notice · Terms of Use
This policy defines the information security and privacy program of ZAP BRABO TECHNOLOGY LTDA ("ZapBrabo") and the controls applied to protect the confidentiality, integrity and availability of the data we process — including data received from partner platforms and personal data belonging to our clients and to their customers.
It is written to satisfy, in a single document, the security program requirements of the commerce and messaging platforms we integrate with, and to comply with Brazilian Law No. 13.709/2018 (LGPD).
This policy applies to all systems, environments, personnel and third parties involved in operating the ZapBrabo platform. In scope:
ZapBrabo is a small technology company. In accordance with the principle that a security program must be appropriate to the nature, size and complexity of the business, responsibilities are consolidated as follows:
Security Officer — Murilo Martins, Founder and Technical Lead. Accountable for this policy, for the security program, for incident response, and for communication with partner platforms on security matters. Contact: contato@zapbrabo.com
Any change to the Security Officer or to the security contact is communicated to affected partner platforms within the timeframe each platform requires.
All personnel with access to production systems must read and accept this policy before access is granted, and access is revoked within 24 hours of the cessation of the need for such access.
| Class | Examples | Handling |
|---|---|---|
| Restricted | Access tokens, API secrets, passwords, customer tax IDs (CPF/CNPJ) | Encrypted at rest, never logged, never transmitted outside TLS, access limited to the Security Officer |
| Confidential | End-customer conversations, contact records, order data, platform-provided data | Encrypted in transit, logically segregated per tenant, retention-limited |
| Internal | Application logs, operational metrics | No personal data retained beyond the defined retention period |
| Public | Marketing site, this policy, terms and privacy notice | No restriction |
Data received from partner platforms is treated as Confidential or Restricted depending on content, is never used for any purpose other than providing the contracted service, and is never sold, shared or used to train third-party models.
ufw) enforces default-deny inbound. Only HTTP (80) and HTTPS (443) are exposed to the internet; the SSH port is not reachable from the internet, password authentication over SSH is disabled and the root account accepts key-based authentication only. The database listens on the local interface only and is never exposed.fail2ban) monitors authentication and service logs and automatically blocks source addresses exhibiting brute-force or abusive patterns.Cache-Control: no-store so that a browser cannot redisplay them after logout.composer audit for PHP and npm audit for JavaScript) are executed against the lockfiles on every release; advisories are remediated by upgrading the affected package. As of 3 September 2026 the production lockfiles carry zero known security advisories, and the runtime (PHP and Node.js) is kept on supported release lines. These audits, together with secret scanning of the full repository history, also run automatically in continuous integration on every change to the main branch and on a weekly schedule; a failing check blocks the change.contato@zapbrabo.com, as published in our Privacy Notice.An information security incident is any actual or suspected unauthorised access to, disclosure of, alteration of or loss of data under our control.
1. Detect and contain. On detection, the Security Officer immediately takes measures to limit the impact, including revoking credentials, blocking access and isolating affected components.
2. Notify. Affected partner platforms are notified through the channel and within the deadline each platform requires — and in any event no later than 24 hours from becoming aware, when the platform specifies that deadline. The Brazilian National Data Protection Authority (ANPD) and affected data subjects are notified where LGPD requires it.
3. Investigate. Evidence, including relevant logs, is preserved for the duration of the investigation and for as long as any partner platform requires.
4. Report. A written report is produced describing the extent of the incident, the data involved, the corrective actions taken and the measures adopted to prevent recurrence.
5. Remediate. Root causes are addressed and this policy is updated where the incident reveals a gap.
ZapBrabo uses the following categories of sub-processor. Each is bound by its own terms and, where personal data is processed, by obligations no less restrictive than those in this policy:
| Sub-processor | Purpose | Location |
|---|---|---|
| DigitalOcean LLC | Application hosting and infrastructure | United States |
| Meta Platforms, Inc. | WhatsApp Business Platform messaging | United States |
| Anthropic PBC | AI language processing | United States |
| OpenAI, L.L.C. | AI language and speech processing | United States |
| Asaas Gestão Financeira S.A. | Payment processing | Brazil |
| Resend, Inc. | Transactional e-mail delivery | United States |
| Google LLC | Calendar integration, when enabled by the client | United States |
| Cartesia, Inc. / ElevenLabs, Inc. | Voice synthesis for audio replies | United States |
Data received from a commerce platform is never transmitted to another commerce platform, and is logically segregated per tenant so that no client can access another client's data.
Source code is replicated in a remote version control repository, allowing the application to be rebuilt from a known state. Infrastructure is reproducible from documented provisioning procedures. Recovery objectives are set in proportion to the service level committed to clients.
The database is backed up by a daily full dump whose integrity is verified automatically (table count and end-of-dump marker; an incomplete dump is rejected) and by a weekly provider-level snapshot of the server. A failed backup raises an immediate alert to the Security Officer.
Each verified dump is additionally encrypted (AES-256) and copied off-site to an independent storage provider (Backblaze B2, US region) every day. The copy is encrypted before it leaves the server, with a key that is not held by the storage provider; the credential used by the server is restricted to that bucket and is write-only, so a compromise of the production server cannot read or delete existing off-site copies. Each encrypted copy is decrypted and compared byte-for-byte with the original before upload, and the upload is verified by checksum. Off-site copies are retained for 30 days. A restore test from the off-site copy (download, decryption and full import into a scratch database, with table counts compared against production) was performed on 3 September 2026 and is repeated at least quarterly; the procedure is documented in a runbook kept with the source code.
This policy is reviewed at least annually and whenever there is a material change to our systems, to the data we process, or to the requirements of a partner platform. Material changes affecting the security of partner-provided data are communicated to affected platforms in writing within the timeframe each platform requires.
Consistent with a security program proportionate to our size, the following controls are formally scheduled. This section is published as part of the policy in the interest of transparency.
Implemented (with date of entry into production):
| Control | Date |
|---|---|
| Automated enforcement of the 90-day personal data retention limit | 12 Aug 2026 |
| Redaction of personal identifiers from application logs | 12 Aug 2026 |
| 90-day log retention with rotation and compression | 12 Aug 2026 |
| HTTP security headers (HSTS and four others) | 12 Aug 2026 |
| Endpoint anti-malware with scheduled scanning | 12 Aug 2026 |
| Scoped, read-only reviewer accounts for platform assessors | 12 Aug 2026 |
| Mandatory multi-factor authentication (TOTP) on administrative and partner panels | 19 Aug 2026 |
| SSH not exposed to the internet; key-only root; password authentication disabled | 19 Aug 2026 |
| Verified daily database backups with failure alerting | 19 Aug 2026 |
| Human confirmation gate for destructive or financially material AI actions | 19 Aug 2026 |
| Client media served only through authenticated, ownership-checked routes | 19 Aug 2026 |
| Content-Security-Policy header | Aug 2026 |
| Audit trail table for sensitive actions (actor, tenant, action, target, IP) | 26 Aug 2026 |
| Dependency audit with zero known advisories (PHP and JavaScript); runtime on supported Node.js 22 | 3 Sep 2026 |
| Automated tenant-isolation test suite (cross-tenant read, write and injection attempts rejected) | 3 Sep 2026 |
| CI security gate on every change and weekly: dependency audit (PHP and JavaScript) and secret scanning of the full repository history | 3 Sep 2026 |
| Encrypted off-site database backups in a second provider (write-only credential, 30-day retention), with restore test performed | 3 Sep 2026 |
Scheduled:
| Control | Target |
|---|---|
| Quarterly internal and external vulnerability scanning | Q4 2026 |
| Independent application security assessment | Subject to platform requirement |
Approved by
Murilo Martins — Founder and Security Officer
ZAP BRABO TECHNOLOGY LTDA
3 September 2026 (v1.2) — supersedes v1.1 of 12 August 2026
Published at zapbrabo.com. This policy is a public document and may be shared with partner platforms, clients and auditors.