Tevlio
Products Tevlio Mail → Private email built around security and control. Tevlio DNS → Clear, accountable DNS for organizations. Tevlio Git → A code home built around company ownership. Tevlio Drive → Company files with access and ownership attached.
Resources Blog → Notes on engineering, products, and the work behind them. Help and support → Get answers or contact the right team. Service status→ Check the current health of Tevlio services. Policies and commitments → Privacy, security, terms, and subprocessors.
Products
Products Tevlio Mail → Private email built around security and control. Tevlio DNS → Clear, accountable DNS for organizations. Tevlio Git → A code home built around company ownership. Tevlio Drive → Company files with access and ownership attached.
Resources
Resources Blog → Notes on engineering, products, and the work behind them. Help and support → Get answers or contact the right team. Service status→ Check the current health of Tevlio services. Policies and commitments → Privacy, security, terms, and subprocessors.
Log in
Log in
Back to Policies

Security Overview

How Tevlio protects its Services, data, and infrastructure.

Last updated
2026-08-10 21:06:14 UTC
Revision
5091e75
Version historyReview every change made to this document on GitHub.
On this page
  • 1. Security responsibilities
  • 2. Access and authentication
  • 3. Infrastructure and data protection
  • 4. Software and change security
  • 5. Monitoring and incidents
  • 6. Availability, recovery, and deletion
  • 7. Providers and payment data
  • 8. Customer responsibilities
  • 9. Vulnerability reporting
On this page
  • 1. Security responsibilities
  • 2. Access and authentication
  • 3. Infrastructure and data protection
  • 4. Software and change security
  • 5. Monitoring and incidents
  • 6. Availability, recovery, and deletion
  • 7. Providers and payment data
  • 8. Customer responsibilities
  • 9. Vulnerability reporting

This overview explains Tevlio’s current security practices at a general level. Controls vary according to the Service, architecture, data, and risk. No system is immune from every threat, and this overview is not a certification or a guarantee that every incident or interruption can be prevented.

For Customer Personal Data governed by a DPA, the minimum contractual controls in DPA Schedule 2 control if they conflict with this overview.

The Portuguese (Brazil) version is the original and controls if this English translation conflicts with it, unless a signed agreement with the Customer says otherwise.

1. Security responsibilities

Tevlio assigns responsibility for security, privacy, infrastructure, access management, and incident response. People authorized to access Customer Personal Data are bound by confidentiality obligations and receive access only for legitimate operational needs.

Tevlio does not claim that its own systems are currently SOC 2 certified. Payment-card and Pix providers are responsible for the security and regulatory requirements within their own payment environments.

2. Access and authentication

Administrative access is limited according to role and need. Depending on the system, protections include individual accounts or keys, least-privilege permissions, encrypted administrative channels, key-based server access, multi-factor authentication where supported, access revocation, and logging appropriate to the risk.

Where Tevlio directly manages passwords, they are stored using a one-way, memory-hard password-hashing method. Two-factor authentication is available for Customer Accounts in supported Services.

Production credentials, encryption keys, and other secrets are restricted to authorized systems and personnel and are replaced or rotated when exposure or risk requires it.

3. Infrastructure and data protection

Tevlio protects web and API traffic with HTTPS and TLS. Other protocols use transport encryption where supported and appropriate. Stored data may be protected through application-level encryption, provider storage encryption, or both, according to the Service architecture.

Authorization and logical-separation controls are designed to prevent one Account from accessing another Account’s data. Tevlio-managed infrastructure uses network restrictions, firewalls, rate limits, and abuse protections appropriate to the exposed service.

Tevlio operates infrastructure in Brazil and also uses providers in other countries. Current providers, purposes, data categories, and processing locations are listed in our Vendors and Subprocessors List . International transfers are explained in our Privacy Policy .

Physical security for hosted systems is operated by the applicable data-center and infrastructure providers.

4. Software and change security

Application and infrastructure changes are maintained in source control. Tevlio uses automated checks, testing, manual review, dependency monitoring, controlled deployment, and rollback procedures according to the risk and nature of the change.

Vulnerabilities are prioritized using factors such as exploitability, impact, exposure, and available mitigations. Remediation time therefore depends on risk rather than a promise that every update will be installed immediately.

Production Customer Personal Data is not intended for development or testing unless its use is necessary, specifically authorized, and protected.

5. Monitoring and incidents

Tevlio maintains operational and security logs, monitoring, and alerts appropriate to each system. Access to logs is restricted, and Customer Content is not intentionally included unless necessary for the relevant function or investigation.

Our incident process covers identification, triage, containment, evidence preservation, investigation, remediation, recovery, required communications, and corrective action where appropriate.

When Tevlio acts as an Operator or Processor, it informs the affected Customer without undue delay after becoming aware of a Personal Data Incident involving Customer Personal Data. When Tevlio acts as Controller, it notifies affected people and authorities, including the ANPD, when and within the time required by applicable law. An outage, vulnerability, or operational event is not necessarily a reportable personal-data incident.

6. Availability, recovery, and deletion

Depending on the Service and data type, Tevlio uses combinations of redundancy, replication, object-storage recovery copies, backups, health monitoring, and restoration procedures. These measures reduce risk but cannot guarantee that every interruption or loss will be prevented or that every recovery copy will always be usable.

Customers should maintain independent exports or backups where a Service supports or recommends them. A specific recovery-time, recovery-point, or backup guarantee applies only when stated in a signed agreement.

Active data and recovery copies may follow different deletion cycles. Retention, Account termination, and deletion are governed by the Privacy Policy , the DPA , Customer instructions, and applicable law.

7. Providers and payment data

Before a Subprocessor handles Customer Personal Data, Tevlio requires contractual privacy, confidentiality, security, incident, deletion, assistance, and international-transfer protections appropriate to its role. Provider details are published in our Vendors and Subprocessors List .

Full payment-card numbers and card security codes are submitted directly to the applicable payment provider and are not intentionally stored by Tevlio. Payment providers may process payment, transaction, identity, fraud-prevention, and compliance information according to the payment method. Tevlio retains only the billing and transaction information needed for the Services, accounting, fraud prevention, support, and legal obligations.

8. Customer responsibilities

Customers are responsible for managing authorized users, protecting credentials and recovery methods, enabling available two-factor authentication, securing their own devices and networks, reviewing Account activity, and maintaining independent exports where appropriate.

Customers should not send passwords, private keys, payment-card security codes, or unnecessary personal data through support requests.

9. Vulnerability reporting

Report suspected vulnerabilities through our security support channel . Include the affected asset, reproduction steps, potential impact, and a secure way to contact you. Do not include personal data or exploit data beyond what is necessary to explain the issue.

Tevlio considers good-faith security testing authorized under this overview only when the researcher:

  • tests only Tevlio-owned assets or assets for which Tevlio has expressly authorized testing;
  • avoids accessing, copying, changing, retaining, or disclosing another person’s data and stops immediately if accidental access occurs;
  • does not perform denial-of-service, destructive, persistence, malware, ransomware, spam, social-engineering, or physical-security testing;
  • reports the issue promptly and allows a reasonable period for investigation and remediation before public disclosure; and
  • does not demand payment or threaten disclosure.

Tevlio will not initiate legal action solely for good-faith research that follows these rules. This statement does not authorize unlawful conduct, bind third parties or public authorities, or promise a reward. Any reward or public attribution must be separately agreed in writing.

Questions about this overview may be submitted through our security support channel .

More policies and commitments

Explore the rest of Tevlio’s policies, terms, and commitments.

Data Processing Addendum Terms that apply when Tevlio processes personal data on behalf of a Customer. → Privacy Policy What personal data Tevlio processes, why and where it is processed, and how to exercise your rights. → Terms of Service Terms that apply to business subscriptions and use of Tevlio Services. → Vendors and Subprocessors Third parties that help Tevlio operate its services and process personal data. →
Back to Policies Back to Top

Useful links

Help and support Service status

Us

Blog

Legal

Privacy Policy Terms of Service All legal policies

Follow us

© 2018–2026 Tevlio. All rights reserved. Tevlio Tecnologia da Informação Ltda. CNPJ 68.407.558/0001-20

English (US) Português (Brasil)