Information Security Program
How security is governed at SemantiqWall - roles, risk management, policy exceptions, annual review and the register of laws and commitments we follow.
As políticas que regem a segurança da SemantiqWall. Elas descrevem o que existe hoje; o que ainda não existe aparece como compromisso, com responsável e prazo.
Documento em inglês As políticas do programa de segurança são publicadas em inglês.
How security is governed at SemantiqWall - roles, risk management, policy exceptions, annual review and the register of laws and commitments we follow.
Who can access what - mandatory MFA, roles and least privilege, account creation and removal, access reviews, server access by SSH keys and handling of secrets.
What is encrypted in transit and at rest today, which algorithms are used, where keys live, and how keys are rotated, revoked and destroyed - including what is not encrypted yet.
How code and configuration change safely - the secure development lifecycle, mandatory tests, review, dependency updates, deployment, rollback and emergency changes.
What SemantiqWall logs, how the audit trail is protected, how long logs are kept, who can read them, how time is synchronized and which alerts are still missing.
How SemantiqWall detects, triages, contains and recovers from security incidents, when and how customers, the ANPD and other authorities are notified, and how evidence is preserved.
What SemantiqWall can recover from today, honest recovery targets, how backups are taken and tested, the disaster recovery steps and the off-site backup gap being closed.
How SemantiqWall finds, rates and fixes vulnerabilities - the public disclosure program, patching deadlines, CVSS and CISA KEV prioritization, dependency scanning and advisories.
What data SemantiqWall holds, how it is classified, where it is stored, how long it is kept, how it is deleted, and how data subject and law enforcement requests are handled.
The suppliers SemantiqWall depends on, what data each one receives, who is responsible for what, and how suppliers are chosen and reviewed.
Rules for using company systems and devices, the security settings required on every device that reaches production or customer data, and the personnel controls that start with the first hire.
What SemantiqWall secures and what each customer must do - users and MFA, API keys, policies, agent integration and approvals.
Dúvidas sobre segurança ou privacidade: contato@semantiqwall.com