This overview explains Tevlio’s current security practices at a general level. Controls vary according to the Service, architecture, data, and risk. No system is immune from every threat, and this overview is not a certification or a guarantee that every incident or interruption can be prevented.
For Customer Personal Data governed by a DPA, the minimum contractual controls in DPA Schedule 2 control if they conflict with this overview.
The Portuguese (Brazil) version is the original and controls if this English translation conflicts with it, unless a signed agreement with the Customer says otherwise.
1. Security responsibilities
Tevlio assigns responsibility for security, privacy, infrastructure, access management, and incident response. People authorized to access Customer Personal Data are bound by confidentiality obligations and receive access only for legitimate operational needs.
Tevlio does not claim that its own systems are currently SOC 2 certified. Payment-card and Pix providers are responsible for the security and regulatory requirements within their own payment environments.
2. Access and authentication
Administrative access is limited according to role and need. Depending on the system, protections include individual accounts or keys, least-privilege permissions, encrypted administrative channels, key-based server access, multi-factor authentication where supported, access revocation, and logging appropriate to the risk.
Where Tevlio directly manages passwords, they are stored using a one-way, memory-hard password-hashing method. Two-factor authentication is available for Customer Accounts in supported Services.
Production credentials, encryption keys, and other secrets are restricted to authorized systems and personnel and are replaced or rotated when exposure or risk requires it.
3. Infrastructure and data protection
Tevlio protects web and API traffic with HTTPS and TLS. Other protocols use transport encryption where supported and appropriate. Stored data may be protected through application-level encryption, provider storage encryption, or both, according to the Service architecture.
Authorization and logical-separation controls are designed to prevent one Account from accessing another Account’s data. Tevlio-managed infrastructure uses network restrictions, firewalls, rate limits, and abuse protections appropriate to the exposed service.
Tevlio operates infrastructure in Brazil and also uses providers in other countries. Current providers, purposes, data categories, and processing locations are listed in our Vendors and Subprocessors List . International transfers are explained in our Privacy Policy .
Physical security for hosted systems is operated by the applicable data-center and infrastructure providers.
4. Software and change security
Application and infrastructure changes are maintained in source control. Tevlio uses automated checks, testing, manual review, dependency monitoring, controlled deployment, and rollback procedures according to the risk and nature of the change.
Vulnerabilities are prioritized using factors such as exploitability, impact, exposure, and available mitigations. Remediation time therefore depends on risk rather than a promise that every update will be installed immediately.
Production Customer Personal Data is not intended for development or testing unless its use is necessary, specifically authorized, and protected.
5. Monitoring and incidents
Tevlio maintains operational and security logs, monitoring, and alerts appropriate to each system. Access to logs is restricted, and Customer Content is not intentionally included unless necessary for the relevant function or investigation.
Our incident process covers identification, triage, containment, evidence preservation, investigation, remediation, recovery, required communications, and corrective action where appropriate.
When Tevlio acts as an Operator or Processor, it informs the affected Customer without undue delay after becoming aware of a Personal Data Incident involving Customer Personal Data. When Tevlio acts as Controller, it notifies affected people and authorities, including the ANPD, when and within the time required by applicable law. An outage, vulnerability, or operational event is not necessarily a reportable personal-data incident.
6. Availability, recovery, and deletion
Depending on the Service and data type, Tevlio uses combinations of redundancy, replication, object-storage recovery copies, backups, health monitoring, and restoration procedures. These measures reduce risk but cannot guarantee that every interruption or loss will be prevented or that every recovery copy will always be usable.
Customers should maintain independent exports or backups where a Service supports or recommends them. A specific recovery-time, recovery-point, or backup guarantee applies only when stated in a signed agreement.
Active data and recovery copies may follow different deletion cycles. Retention, Account termination, and deletion are governed by the Privacy Policy , the DPA , Customer instructions, and applicable law.
7. Providers and payment data
Before a Subprocessor handles Customer Personal Data, Tevlio requires contractual privacy, confidentiality, security, incident, deletion, assistance, and international-transfer protections appropriate to its role. Provider details are published in our Vendors and Subprocessors List .
Full payment-card numbers and card security codes are submitted directly to the applicable payment provider and are not intentionally stored by Tevlio. Payment providers may process payment, transaction, identity, fraud-prevention, and compliance information according to the payment method. Tevlio retains only the billing and transaction information needed for the Services, accounting, fraud prevention, support, and legal obligations.
8. Customer responsibilities
Customers are responsible for managing authorized users, protecting credentials and recovery methods, enabling available two-factor authentication, securing their own devices and networks, reviewing Account activity, and maintaining independent exports where appropriate.
Customers should not send passwords, private keys, payment-card security codes, or unnecessary personal data through support requests.
9. Vulnerability reporting
Report suspected vulnerabilities through our security support channel . Include the affected asset, reproduction steps, potential impact, and a secure way to contact you. Do not include personal data or exploit data beyond what is necessary to explain the issue.
Tevlio considers good-faith security testing authorized under this overview only when the researcher:
- tests only Tevlio-owned assets or assets for which Tevlio has expressly authorized testing;
- avoids accessing, copying, changing, retaining, or disclosing another person’s data and stops immediately if accidental access occurs;
- does not perform denial-of-service, destructive, persistence, malware, ransomware, spam, social-engineering, or physical-security testing;
- reports the issue promptly and allows a reasonable period for investigation and remediation before public disclosure; and
- does not demand payment or threaten disclosure.
Tevlio will not initiate legal action solely for good-faith research that follows these rules. This statement does not authorize unlawful conduct, bind third parties or public authorities, or promise a reward. Any reward or public attribution must be separately agreed in writing.
Questions about this overview may be submitted through our security support channel .