JANELA AMBICIOSA

Information security

What we do with
your information.

Access management, encryption, backups and incident response. We apply to client data what we recommend to clients.

Frameworks

We are not, at this date, a certified organisation. The controls below follow the structure of ISO/IEC 27001 and the NIST Cybersecurity Framework, used as an organising reference and not as a claim of certification. Where a control is not yet in force, it is marked as such.

Classification and access

Client information is classified as confidential by default. Access is granted only to those working on the project, for as long as the project lasts, and is reviewed at closure.

Two-factor authentication is mandatory on every service holding client information. Passwords are unique per service and held in a password manager; they are never shared by email or message.

Encryption

Information is encrypted in transit, using TLS, and at rest, through the encryption capabilities of the services used. This website is served exclusively over HTTPS, with HSTS enabled.

Hosting and data location

The services used host data within the European Economic Area. Where a subprocessor handles data outside the EEA, appropriate safeguards under Chapter V of the GDPR apply and the client is informed.

Backups

Backups run daily and are held separately from the source system. Restoration is tested periodically — a backup that has never been tested is not a backup, it is a hope.

Incident management

There is a four-step procedure: detection, containment, analysis and communication. Where an incident involves personal data and poses a risk to data subjects, the Portuguese Data Protection Authority is notified within 72 hours and affected clients are informed without undue delay.

Suppliers

Every service with access to client information is assessed before adoption and is subject to a data processing agreement under Article 28 GDPR. The list of subprocessors is available on request.

Vulnerability disclosure

Vulnerabilities in this website can be reported to the address listed at /.well-known/security.txt. We acknowledge receipt within three business days and keep the reporter informed until resolution. We do not pursue legal action against good-faith research.

Security of this website

This site loads no third-party resources: fonts are served from our own domain, there is no external analytics, no iframes and no content delivery network involved. That allows a strict Content-Security-Policy and means a visit to this site is not observable by third parties.

Controls

The real status of each control in this area. A control "being implemented" is defined and pending approval; "planned" has a target date but is not yet written.

  • Two-factor authentication

    Mandatory on all services holding client data.

    In force
  • Encryption in transit and at rest

    TLS and service-level encryption.

    In force
  • Daily backups

    Held separately; restoration tested.

    In force
  • Incident procedure

    Drafted; tabletop exercise pending.

    Being implemented
  • Formal supplier assessment

    Criteria defined; register to be formalised.

    Planned
  • security.txt published

    Responsible disclosure channel active.

    In force

Documents in this area

  • Information Security Policy

    Being implemented

    Information classification, access management, authentication, encryption, backups and acceptable use of equipment.

    Version
    1.0
    Available once approved
  • Incident Management Procedure

    Being implemented

    Detection, classification, containment and communication of security incidents, including the 72-hour deadline for notifying personal data breaches.

    Version
    1.0
    Available once approved
  • Supplier Management Policy

    Planned

    Selection and assessment criteria for subprocessors with access to client information, and the minimum contractual clauses required.

    Version
    1.0
    Not yet drafted

Need documentation for a process?

We send the due diligence pack within 24 business hours, with the registry certificate, beneficial ownership, corporate structure and the applicable policies.

Request documentation