Legal Document
Version 1.0 · June 2026
Aranis was built with security as a design requirement, not an added layer. Our controls are based on ISO 27001, NIST CSF 2.0, and the LGPD, and apply across the whole chain — platform, infrastructure, data, and vendors.
Our delivery pipeline includes static analysis (SAST), software composition analysis (SCA), and dynamic testing (DAST) run continuously. Dependencies are audited on every release. Packages with critical vulnerabilities (CVSS ≥ 9.0) are blocked without a documented mitigation plan. Production deploys follow a controlled process with rollback capability within minutes.
| Classification | Controls |
|---|---|
| Customer and assessment data | Encryption at rest (AES-256), TLS 1.2+ in transit, per-tenant isolation |
| Credentials and secrets | Never stored in plain text |
| Logs and metrics | Internal access, controlled retention |
| Public content | No restrictions |
All customer data is isolated per organization — no customer accesses another's data. Automatic backups with a minimum 7-day retention.
We monitor availability, production errors, and vulnerabilities in real time. Critical alerts are handled within 24 hours. Platform availability is checked every 5 minutes with automatic notifications.
We maintain a formal incident response plan with severity classification and defined communication deadlines. Incidents affecting platform availability for customers are communicated proactively.
Aranis acts as Processor of your customers' end-user data and as Controller of platform-user data. The legal basis for processing is contract performance (Art. 7, V, LGPD).
Main subprocessors: Supabase, Vercel, Cloudflare, Amazon Web Services, Anthropic, OpenAI, Stripe, Resend — all with SOC 2 certifications and GDPR compliance.