Legal Document

Information Security

Version 1.0 · June 2026

Aranis was built with security as a design requirement, not an added layer. Our controls are based on ISO 27001, NIST CSF 2.0, and the LGPD, and apply across the whole chain — platform, infrastructure, data, and vendors.

Access and Identity Management

  • We apply the principle of least privilege across all access
  • Multi-factor authentication (MFA) is mandatory on our internal systems and can be enabled by the user on the SaaS platform
  • No production credential travels over insecure channels
  • Secrets are managed in encrypted vaults with periodic rotation

Code and Delivery Security

Our delivery pipeline includes static analysis (SAST), software composition analysis (SCA), and dynamic testing (DAST) run continuously. Dependencies are audited on every release. Packages with critical vulnerabilities (CVSS ≥ 9.0) are blocked without a documented mitigation plan. Production deploys follow a controlled process with rollback capability within minutes.

Data Protection

ClassificationControls
Customer and assessment dataEncryption at rest (AES-256), TLS 1.2+ in transit, per-tenant isolation
Credentials and secretsNever stored in plain text
Logs and metricsInternal access, controlled retention
Public contentNo restrictions

All customer data is isolated per organization — no customer accesses another's data. Automatic backups with a minimum 7-day retention.

Continuous Monitoring

We monitor availability, production errors, and vulnerabilities in real time. Critical alerts are handled within 24 hours. Platform availability is checked every 5 minutes with automatic notifications.

Incident Response

We maintain a formal incident response plan with severity classification and defined communication deadlines. Incidents affecting platform availability for customers are communicated proactively.

LGPD and Privacy

Aranis acts as Processor of your customers' end-user data and as Controller of platform-user data. The legal basis for processing is contract performance (Art. 7, V, LGPD).

  • No data is shared with third parties for advertising purposes
  • Data-subject requests answered within 15 business days via privacy@aranis.ai
  • In the event of an incident exposing personal data, the ANPD is notified within 2 business days (Art. 48 LGPD)

Main subprocessors: Supabase, Vercel, Cloudflare, Amazon Web Services, Anthropic, OpenAI, Stripe, Resend — all with SOC 2 certifications and GDPR compliance.

Questions or Vulnerability Reports