Security & Compliance Center
Transparency is part of our security culture. Select the security and compliance documents you'd like to receive and our team will send them to your corporate email.
Monitoring
Security controls active on the platform, organized by domain.
Application Security
- Encryption in transit (TLS 1.2+)
- Encryption of data at rest
- Server-side input validation
- Rate limiting and abuse protection
- Secure sessions and CSRF protection
- Audit trails for administrative actions
- Automated regression testing
Infrastructure Security
- Cloud hosting (AWS — Amazon Web Services)
- Managed database
- Automated database backups
- Environment segregation (development / production)
- Centralized secrets and credentials management
- Production monitoring and logging
Organizational Security
- Documented information security policies
- Incident response plan
- Business continuity plan
- Third-party risk management
- Privacy program (LGPD / GDPR)
- Code of conduct and awareness
Penetration testing (pentest)
We perform periodic penetration tests on the application. The executive summary of the most recent test can be requested along with the other documents.
Available documents
Select one or more documents below.
Information Security Policy
Corporate information security guidelines, roles, responsibilities and protection principles.
Privacy Governance & Data Protection Policy
Privacy governance framework, legal bases and LGPD/GDPR compliance.
Application Privacy Notice
How the platform collects, uses and protects personal data of application users.
Data Retention & Secure Disposal Policy
Data retention periods and secure disposal procedures at end of lifecycle.
Data Classification & Handling Policy
Information classification levels and handling rules for each data category.
Identity & Access Management Policy
Authentication, authorization, least-privilege controls and periodic access reviews.
Incident Response & Customer Notification Plan
Security incident detection, containment and response process, including customer communication.
Business Continuity & Disaster Recovery Plan
Operational continuity strategies, RTO/RPO and disaster recovery procedures.
Backup Policy
Frequency, retention, encryption and restore testing of platform backups.
Technical Security Standard — Cloud Application
Cloud application technical controls: encryption, hardening, segregation and monitoring.
Third-Party Risk Management Policy
Assessment and monitoring of risks from vendors and partners with access to data or systems.
AI Governance Standard
Principles and controls for responsible use of artificial intelligence on the platform.
System Architecture & Data Flow Overview
High-level platform architecture and mapping of data flows between components.
Code of Conduct
Ethical and conduct standards expected of JettaCargo employees and partners.
Penetration Test Report — Executive Summary
Executive summary of the most recent penetration test: scope, methodology and key findings. The full technical report may be made available under NDA.
Subprocessors
Vendors that process data on our behalf, with purpose and data location.
- AWS (Amazon Web Services) — Application hosting and cloud infrastructure (United States)
- Banco de dados gerenciado — Application data storage (leads and simulations) (United States)
- HERE Maps — Maps and geolocation — used only in the routing module (Netherlands / European Union)
- Mapbox — Maps and geolocation — used only in the routing module (United States)
- Google Maps — Maps and geolocation — used only in the routing module (United States)
Compliance
Our honest position on reference laws and standards — without claiming certifications we don't hold.
LGPD
We operate in compliance with Brazil's General Data Protection Law (LGPD, Law 13.709/2018): mapped legal bases, data subject rights honored, a designated DPO and a documented privacy program.
GDPR
Our privacy practices follow the principles of the EU General Data Protection Regulation for European visitor and customer data, including cookie consent and data minimization.
ISO 27001
Our security policies and controls are structured around ISO/IEC 27001 practices. We do not hold a formal certification — we state alignment, not certification.
Security FAQ
Answers to the most common questions from vendor security questionnaires.
Is data encrypted?
Yes. All traffic between browsers and our servers uses TLS 1.2 or higher, and data stored in the database is encrypted at rest by the managed cloud infrastructure.
How do backups work?
The database has automated backups performed by the managed infrastructure, with retention and restore procedures defined in our Backup Policy, available upon request below.
What happens in the event of a security incident?
We maintain a documented Incident Response Plan covering detection, containment, eradication and communication. Affected customers are notified within the applicable legal timeframes (LGPD/GDPR).
How long is data retained?
We retain personal data only for as long as necessary for the purposes it was collected for, or as required by law. Timeframes and secure disposal procedures are in our Data Retention & Disposal Policy.
How is access to data controlled?
Access follows the least-privilege principle: administrative areas require authentication with secure sessions, sensitive actions are recorded in audit trails, and access is reviewed periodically.
Where is data stored?
Data is stored on managed cloud infrastructure (AWS — Amazon Web Services) in the United States. The full list of subprocessors, with purpose and location, is published on this page.
Do you perform penetration testing?
Yes. We perform periodic penetration tests on the application. The date of the most recent test is highlighted on this page and the executive summary can be requested along with the other documents.
How do I report a vulnerability or ask security questions?
Write to dpo@jettacargo.com.br or use the form on this page. Vendor security questionnaires can also be sent through these channels — our team responds within 5 business days.