Security Policy
Last updated: June 15, 2026
Our Commitment
Bruxus takes the security of our platform and our users’ data seriously. This Security Policy outlines the measures we implement to protect against unauthorized access, data breaches, and other security threats.
Security Architecture
Infrastructure Security
- All services run on SOC 2-compliant cloud infrastructure (AWS/GCP)
- Network segmentation and firewalls limit access between environments
- DDoS protection and web application firewall (WAF) in place
- Regular vulnerability scanning and penetration testing
Data Protection
- Data encrypted at rest using AES-256
- Data encrypted in transit using TLS 1.3
- Secrets managed via vault-based systems with rotation policies
- Database encryption with automatic backup and point-in-time recovery
Access Control
- Role-based access control (RBAC) for all internal systems
- Multi-factor authentication (MFA) required for administrative access
- Principle of least privilege applied to all permissions
- Regular access reviews and audit logging
Application Security
Secure Development Lifecycle
- Code review required for all changes
- Static application security testing (SAST) in CI/CD pipeline
- Dependency scanning for known vulnerabilities
- Container image scanning before deployment
Authentication & Authorization
- OAuth 2.0 / OpenID Connect for authentication
- Session management with secure, HTTP-only cookies
- Rate limiting and brute force protection
- CSRF and XSS protections on all endpoints
Incident Response
We maintain a documented incident response plan that includes:
- Detection and analysis
- Containment and eradication
- Recovery and remediation
- Post-incident review
Vulnerability Disclosure
If you discover a security vulnerability, please contact us at security@bruxus.com. We commit to:
- Acknowledging receipt within 24 hours
- Providing regular updates on remediation progress
- Responsible disclosure coordination
Compliance
Bruxus complies with applicable data protection regulations including GDPR, LGPD, and CCPA. Independent security audits are conducted annually.
Contact
For security-related inquiries, contact security@bruxus.com.
