Compliance

Security and compliance.

This page is the standing answer to a vendor assessment: what we do, what we do not do, where the data lives and who else touches it. Where a certificate belongs to our provider and not to us, it says so.

What we hold ourselves to

Six commitments the rest of this page has to back up.

LGPD by contract

A data processing addendum in every corporate agreement, with purposes, subprocessors and notification deadlines.

Encryption in transit

TLS required along the whole path between browser, site, products and providers.

Least privilege

Each organisation sees only its own data. Access rules live in the database, not just in the application.

Two-factor for the team

Two-factor authentication required on the providers' admin accounts.

Provider backups

Database with automatic backups and point-in-time recovery, per the plan contracted with Supabase.

Review before release

Every change goes through human review, automated checks and a preview environment before production.

What we are measured against

The ledger.

GL Suite is small. Rather than claim accreditations we do not have, we state where a certificate exists, whose it is, and where we align our own practice to the criteria.

StandardStatus
LGPDContractual, via data processing addendum
ISO 27001Aligned practice · providers' certificate (Vercel, Supabase, Stripe)
SOC 2Providers' certificate · reports on request
PCI DSSStripe's certificate; we do not store card data
GDPRContractual, where there are data subjects in the EU
Data residency

Where the data lives.

What is verifiable today. What varies per project is stated as variable.

Site and products

São Paulo, Brazil (Vercel gru1)

Applications served from the São Paulo region, fixed in the project configuration.

Database and files

Region per project (Supabase)

The database region is chosen per project and agreed by contract where there is a residency requirement.

Subprocessors

Who processes data on our behalf.

Services that run the site and the products. Changes to this list are communicated to customers under contract.

Before anything goes live

Four gates between a commit and production.

Peer review

Every change gets a second pair of eyes before it goes in.

Automated checks

Types, lint and dependency scanning run on every change.

Preview

Every change becomes a preview environment before production, under the same controls.

External assessment

Third-party penetration testing when the contract calls for it, fixed by severity.

Need a security package?

Vendor questionnaire, data addendum or architecture review: write to us and we put the package together for your case.

Compliance | GL Suite