Security and compliance.
This page is the standing answer to a vendor assessment: what we do, what we do not do, where the data lives and who else touches it. Where a certificate belongs to our provider and not to us, it says so.
Six commitments the rest of this page has to back up.
LGPD by contract
A data processing addendum in every corporate agreement, with purposes, subprocessors and notification deadlines.
Encryption in transit
TLS required along the whole path between browser, site, products and providers.
Least privilege
Each organisation sees only its own data. Access rules live in the database, not just in the application.
Two-factor for the team
Two-factor authentication required on the providers' admin accounts.
Provider backups
Database with automatic backups and point-in-time recovery, per the plan contracted with Supabase.
Review before release
Every change goes through human review, automated checks and a preview environment before production.
The ledger.
GL Suite is small. Rather than claim accreditations we do not have, we state where a certificate exists, whose it is, and where we align our own practice to the criteria.
| Standard | Status |
|---|---|
| LGPD | Contractual, via data processing addendum |
| ISO 27001 | Aligned practice · providers' certificate (Vercel, Supabase, Stripe) |
| SOC 2 | Providers' certificate · reports on request |
| PCI DSS | Stripe's certificate; we do not store card data |
| GDPR | Contractual, where there are data subjects in the EU |
Where the data lives.
What is verifiable today. What varies per project is stated as variable.
São Paulo, Brazil (Vercel gru1)
Applications served from the São Paulo region, fixed in the project configuration.
Region per project (Supabase)
The database region is chosen per project and agreed by contract where there is a residency requirement.
Who processes data on our behalf.
Services that run the site and the products. Changes to this list are communicated to customers under contract.
Four gates between a commit and production.
Peer review
Every change gets a second pair of eyes before it goes in.
Automated checks
Types, lint and dependency scanning run on every change.
Preview
Every change becomes a preview environment before production, under the same controls.
External assessment
Third-party penetration testing when the contract calls for it, fixed by severity.
Need a security package?
Vendor questionnaire, data addendum or architecture review: write to us and we put the package together for your case.