CatracaCatraca Fleet

Security

Security, privacy, and the boring parts done right.

Operating a delivery business means handling customer addresses, phone numbers, order details, and payment data. Here is how we protect that and what you can verify yourself.

LGPD & data protection

Catraca complies with Brazil's General Data Protection Law (LGPD) and acts as Data Processor for the personal data your business stores in the platform. You can export or delete that data on demand. We have a DPO and a documented data map.

  • Self-serve data export in CSV/JSON for any account
  • Self-serve account deletion with 30-day soft retention
  • Documented data flows for every collected field
  • DPO contact: [email protected]

Encryption in transit and at rest

All traffic is TLS 1.2+ with HSTS. Databases and object storage are encrypted at rest using AES-256. Internal service-to-service traffic stays inside private networks; nothing crosses the public internet unencrypted.

  • TLS 1.2+ enforced on every public endpoint
  • AES-256 at rest on Postgres and object storage
  • Per-environment encryption keys, no shared keys across stages
  • Secrets in a managed vault, never in code or env files in version control

Infrastructure & access control

We run on commodity cloud infrastructure in São Paulo, with active monitoring and least-privilege access. Internal staff use SSO + MFA and only have access to the systems their role needs.

  • Cloud infrastructure in São Paulo, Brazil (data residency by default)
  • Least-privilege access, reviewed quarterly
  • Background and audit logs retained for 1 year
  • Daily encrypted backups with point-in-time recovery

Incident response

Incidents that affect customers are communicated within 24 hours via email and status page. Security incidents trigger a documented response that includes containment, customer notification, and a post-mortem published within 7 days.

  • 24-hour customer notification target
  • Documented runbooks per incident class
  • Public post-mortems for customer-impacting events
  • Status page (catraca.statuspage.io) for real-time updates

Common questions

Where is my data stored?

Inside Brazil by default (São Paulo region). For US accounts we can host in us-east on request — talk to the team.

Do you share data with third parties?

Only with subprocessors we need to deliver the service (payment gateway, transactional email, monitoring). The list is published and any change is notified 30 days in advance.

Can I audit my data?

Yes. Export anything tied to your account in CSV/JSON from the dashboard. For a deeper audit (system logs, access events), open a ticket with our DPO.

What happens if there is a breach?

We notify affected customers within 24 hours, contain the issue, and publish a post-mortem within 7 days. We also report to ANPD as required by LGPD.