Information security
What we do with
your information.
Access management, encryption, backups and incident response. We apply to client data what we recommend to clients.
Frameworks
We are not, at this date, a certified organisation. The controls below follow the structure of ISO/IEC 27001 and the NIST Cybersecurity Framework, used as an organising reference and not as a claim of certification. Where a control is not yet in force, it is marked as such.
Classification and access
Client information is classified as confidential by default. Access is granted only to those working on the project, for as long as the project lasts, and is reviewed at closure.
Two-factor authentication is mandatory on every service holding client information. Passwords are unique per service and held in a password manager; they are never shared by email or message.
Encryption
Information is encrypted in transit, using TLS, and at rest, through the encryption capabilities of the services used. This website is served exclusively over HTTPS, with HSTS enabled.
Hosting and data location
The services used host data within the European Economic Area. Where a subprocessor handles data outside the EEA, appropriate safeguards under Chapter V of the GDPR apply and the client is informed.
Backups
Backups run daily and are held separately from the source system. Restoration is tested periodically — a backup that has never been tested is not a backup, it is a hope.
Incident management
There is a four-step procedure: detection, containment, analysis and communication. Where an incident involves personal data and poses a risk to data subjects, the Portuguese Data Protection Authority is notified within 72 hours and affected clients are informed without undue delay.
Suppliers
Every service with access to client information is assessed before adoption and is subject to a data processing agreement under Article 28 GDPR. The list of subprocessors is available on request.
Vulnerability disclosure
Vulnerabilities in this website can be reported to the address listed at /.well-known/security.txt. We acknowledge receipt within three business days and keep the reporter informed until resolution. We do not pursue legal action against good-faith research.
Security of this website
This site loads no third-party resources: fonts are served from our own domain, there is no external analytics, no iframes and no content delivery network involved. That allows a strict Content-Security-Policy and means a visit to this site is not observable by third parties.
Controls
The real status of each control in this area. A control "being implemented" is defined and pending approval; "planned" has a target date but is not yet written.
- In force
Two-factor authentication
Mandatory on all services holding client data.
- In force
Encryption in transit and at rest
TLS and service-level encryption.
- In force
Daily backups
Held separately; restoration tested.
- Being implemented
Incident procedure
Drafted; tabletop exercise pending.
- Planned
Formal supplier assessment
Criteria defined; register to be formalised.
- In force
security.txt published
Responsible disclosure channel active.
Documents in this area
-
Information Security Policy
Being implementedInformation classification, access management, authentication, encryption, backups and acceptable use of equipment.
-
Incident Management Procedure
Being implementedDetection, classification, containment and communication of security incidents, including the 72-hour deadline for notifying personal data breaches.
-
Supplier Management Policy
PlannedSelection and assessment criteria for subprocessors with access to client information, and the minimum contractual clauses required.
Need documentation for a process?
We send the due diligence pack within 24 business hours, with the registry certificate, beneficial ownership, corporate structure and the applicable policies.