ZapBrabo
ZAP BRABO
TECHNOLOGY LTDA · CNPJ 66.000.756/0001-49

Information Security Policy

Version 1.2 · Effective 3 September 2026 · Next review 3 September 2027

Download as PDF  ·  Privacy Notice  ·  Terms of Use

Nota em português: este documento é publicado em inglês por ser dirigido também às plataformas internacionais com as quais o ZapBrabo se integra. Para informações sobre tratamento de dados pessoais em português, consulte a Política de Privacidade.

1. Purpose

This policy defines the information security and privacy program of ZAP BRABO TECHNOLOGY LTDA ("ZapBrabo") and the controls applied to protect the confidentiality, integrity and availability of the data we process — including data received from partner platforms and personal data belonging to our clients and to their customers.

It is written to satisfy, in a single document, the security program requirements of the commerce and messaging platforms we integrate with, and to comply with Brazilian Law No. 13.709/2018 (LGPD).

2. Scope

This policy applies to all systems, environments, personnel and third parties involved in operating the ZapBrabo platform. In scope:

3. Organisation and responsibilities

ZapBrabo is a small technology company. In accordance with the principle that a security program must be appropriate to the nature, size and complexity of the business, responsibilities are consolidated as follows:

Security Officer — Murilo Martins, Founder and Technical Lead. Accountable for this policy, for the security program, for incident response, and for communication with partner platforms on security matters. Contact: contato@zapbrabo.com

Any change to the Security Officer or to the security contact is communicated to affected partner platforms within the timeframe each platform requires.

All personnel with access to production systems must read and accept this policy before access is granted, and access is revoked within 24 hours of the cessation of the need for such access.

4. Data classification

ClassExamplesHandling
RestrictedAccess tokens, API secrets, passwords, customer tax IDs (CPF/CNPJ)Encrypted at rest, never logged, never transmitted outside TLS, access limited to the Security Officer
ConfidentialEnd-customer conversations, contact records, order data, platform-provided dataEncrypted in transit, logically segregated per tenant, retention-limited
InternalApplication logs, operational metricsNo personal data retained beyond the defined retention period
PublicMarketing site, this policy, terms and privacy noticeNo restriction

Data received from partner platforms is treated as Confidential or Restricted depending on content, is never used for any purpose other than providing the contracted service, and is never sold, shared or used to train third-party models.

5. Access control

6. Network and infrastructure security

7. Encryption

8. Application security

9. Logging and monitoring

10. Data retention and disposal

11. Incident response

An information security incident is any actual or suspected unauthorised access to, disclosure of, alteration of or loss of data under our control.

1. Detect and contain. On detection, the Security Officer immediately takes measures to limit the impact, including revoking credentials, blocking access and isolating affected components.

2. Notify. Affected partner platforms are notified through the channel and within the deadline each platform requires — and in any event no later than 24 hours from becoming aware, when the platform specifies that deadline. The Brazilian National Data Protection Authority (ANPD) and affected data subjects are notified where LGPD requires it.

3. Investigate. Evidence, including relevant logs, is preserved for the duration of the investigation and for as long as any partner platform requires.

4. Report. A written report is produced describing the extent of the incident, the data involved, the corrective actions taken and the measures adopted to prevent recurrence.

5. Remediate. Root causes are addressed and this policy is updated where the incident reveals a gap.

12. Third parties and sub-processors

ZapBrabo uses the following categories of sub-processor. Each is bound by its own terms and, where personal data is processed, by obligations no less restrictive than those in this policy:

Sub-processorPurposeLocation
DigitalOcean LLCApplication hosting and infrastructureUnited States
Meta Platforms, Inc.WhatsApp Business Platform messagingUnited States
Anthropic PBCAI language processingUnited States
OpenAI, L.L.C.AI language and speech processingUnited States
Asaas Gestão Financeira S.A.Payment processingBrazil
Resend, Inc.Transactional e-mail deliveryUnited States
Google LLCCalendar integration, when enabled by the clientUnited States
Cartesia, Inc. / ElevenLabs, Inc.Voice synthesis for audio repliesUnited States

Data received from a commerce platform is never transmitted to another commerce platform, and is logically segregated per tenant so that no client can access another client's data.

13. Business continuity

Source code is replicated in a remote version control repository, allowing the application to be rebuilt from a known state. Infrastructure is reproducible from documented provisioning procedures. Recovery objectives are set in proportion to the service level committed to clients.

The database is backed up by a daily full dump whose integrity is verified automatically (table count and end-of-dump marker; an incomplete dump is rejected) and by a weekly provider-level snapshot of the server. A failed backup raises an immediate alert to the Security Officer.

Each verified dump is additionally encrypted (AES-256) and copied off-site to an independent storage provider (Backblaze B2, US region) every day. The copy is encrypted before it leaves the server, with a key that is not held by the storage provider; the credential used by the server is restricted to that bucket and is write-only, so a compromise of the production server cannot read or delete existing off-site copies. Each encrypted copy is decrypted and compared byte-for-byte with the original before upload, and the upload is verified by checksum. Off-site copies are retained for 30 days. A restore test from the off-site copy (download, decryption and full import into a scratch database, with table counts compared against production) was performed on 3 September 2026 and is repeated at least quarterly; the procedure is documented in a runbook kept with the source code.

14. Policy governance

This policy is reviewed at least annually and whenever there is a material change to our systems, to the data we process, or to the requirements of a partner platform. Material changes affecting the security of partner-provided data are communicated to affected platforms in writing within the timeframe each platform requires.

15. Continuous improvement programme

Consistent with a security program proportionate to our size, the following controls are formally scheduled. This section is published as part of the policy in the interest of transparency.

Implemented (with date of entry into production):

ControlDate
Automated enforcement of the 90-day personal data retention limit12 Aug 2026
Redaction of personal identifiers from application logs12 Aug 2026
90-day log retention with rotation and compression12 Aug 2026
HTTP security headers (HSTS and four others)12 Aug 2026
Endpoint anti-malware with scheduled scanning12 Aug 2026
Scoped, read-only reviewer accounts for platform assessors12 Aug 2026
Mandatory multi-factor authentication (TOTP) on administrative and partner panels19 Aug 2026
SSH not exposed to the internet; key-only root; password authentication disabled19 Aug 2026
Verified daily database backups with failure alerting19 Aug 2026
Human confirmation gate for destructive or financially material AI actions19 Aug 2026
Client media served only through authenticated, ownership-checked routes19 Aug 2026
Content-Security-Policy headerAug 2026
Audit trail table for sensitive actions (actor, tenant, action, target, IP)26 Aug 2026
Dependency audit with zero known advisories (PHP and JavaScript); runtime on supported Node.js 223 Sep 2026
Automated tenant-isolation test suite (cross-tenant read, write and injection attempts rejected)3 Sep 2026
CI security gate on every change and weekly: dependency audit (PHP and JavaScript) and secret scanning of the full repository history3 Sep 2026
Encrypted off-site database backups in a second provider (write-only credential, 30-day retention), with restore test performed3 Sep 2026

Scheduled:

ControlTarget
Quarterly internal and external vulnerability scanningQ4 2026
Independent application security assessmentSubject to platform requirement

Approved by

Murilo Martins — Founder and Security Officer
ZAP BRABO TECHNOLOGY LTDA
3 September 2026 (v1.2) — supersedes v1.1 of 12 August 2026

Published at zapbrabo.com. This policy is a public document and may be shared with partner platforms, clients and auditors.