Security Policy

Last updated: June 15, 2026

Our Commitment

Bruxus takes the security of our platform and our users’ data seriously. This Security Policy outlines the measures we implement to protect against unauthorized access, data breaches, and other security threats.

Security Architecture

Infrastructure Security

  • All services run on SOC 2-compliant cloud infrastructure (AWS/GCP)
  • Network segmentation and firewalls limit access between environments
  • DDoS protection and web application firewall (WAF) in place
  • Regular vulnerability scanning and penetration testing

Data Protection

  • Data encrypted at rest using AES-256
  • Data encrypted in transit using TLS 1.3
  • Secrets managed via vault-based systems with rotation policies
  • Database encryption with automatic backup and point-in-time recovery

Access Control

  • Role-based access control (RBAC) for all internal systems
  • Multi-factor authentication (MFA) required for administrative access
  • Principle of least privilege applied to all permissions
  • Regular access reviews and audit logging

Application Security

Secure Development Lifecycle

  • Code review required for all changes
  • Static application security testing (SAST) in CI/CD pipeline
  • Dependency scanning for known vulnerabilities
  • Container image scanning before deployment

Authentication & Authorization

  • OAuth 2.0 / OpenID Connect for authentication
  • Session management with secure, HTTP-only cookies
  • Rate limiting and brute force protection
  • CSRF and XSS protections on all endpoints

Incident Response

We maintain a documented incident response plan that includes:

  1. Detection and analysis
  2. Containment and eradication
  3. Recovery and remediation
  4. Post-incident review

Vulnerability Disclosure

If you discover a security vulnerability, please contact us at security@bruxus.com. We commit to:

  • Acknowledging receipt within 24 hours
  • Providing regular updates on remediation progress
  • Responsible disclosure coordination

Compliance

Bruxus complies with applicable data protection regulations including GDPR, LGPD, and CCPA. Independent security audits are conducted annually.

Contact

For security-related inquiries, contact security@bruxus.com.