Pular para o conteúdo principal

Security

Your data stays yours.
No exceptions.

Isolation by design, encryption in transit and at rest, audited infrastructure and human approval on everything that matters. Not marketing — architecture.

The commitment

The commitment that doesn't bend.

Your methodologies, your clients, your conversations, your reports — they're yours. If you leave, you take it all. Our copies are destroyed within 30 days of cancellation.

Guarantees

  • Never shared between workspaces.

    Isolation guaranteed by Row Level Security in Postgres.

  • Infrastructure audited to SOC 2 Type 2 and ISO 27001.

    Certifications for the infrastructure where your data lives.

  • Compliant with the LGPD.

    Personal data processing follows Brazil's General Data Protection Law.

Technical controls

Secure architecture by default.

Workspace isolated by design.

Row Level Security in Postgres guarantees every workspace is an island. No query can return data from another tenant — isolation lives at the database layer, not the application. Even a bug in the code can't cross that boundary.

Encryption in transit and at rest.

Every connection between your browser and the platform runs over TLS. Database, files and backups are encrypted with AES-256 across the infrastructure, with daily database backups.

Human approval on what matters.

The agent prepares, you decide. Sending a proposal, an assessment or any external communication goes through your review before it goes out — it never happens autonomously.

Audit trail of the agent's actions.

Every relevant action by the agent is logged and searchable — what was done, when, and in what context. Not a promise: it's the log that already runs in production.

Certifications

Certified infrastructure.

Your data runs on independently audited infrastructure, and processing follows the LGPD and the GDPR.

AICPA SOC 2 Type II

SOC 2 Type II

Security, availability and confidentiality controls audited by a third party.

ISO

ISO/IEC 27001

Certified information security management system.

ISO

ISO/IEC 27017

Security controls specific to cloud services.

ISO

ISO/IEC 27018

Protection of personal data processed in the cloud.

ISO

ISO/IEC 27701

Information privacy management system.

PCI Security Standards Council

PCI DSS

Payments at the industry's highest level. Cards never touch our servers.

256

AES-256

Database, files and backups encrypted at rest. TLS in transit.

LGPD

LGPD

Designated data officer, documented lawful basis and data subject rights.

GDPR

GDPR

EU/EEA data subjects with documented lawful basis and transfers.

Privacy

LGPD, EU data subjects and responsible disclosure.

LGPD and EU data subjects

Personal data processing follows the LGPD. EU/EEA data subjects have the lawful basis and international transfer details described in the GDPR notice.

Responsible disclosure program

Found a vulnerability? We want to know before anyone else. Report technical details to contact@consultor.app. We respond within 48 hours with confirmation of receipt and a resolution timeline.

Please don't disclose publicly before coordinating with us. Researchers who follow this process get public credit when the fix ships. There's no financial bounty program at this time.

Need technical security details for your InfoSec team's review?

Updated in September 2026