Security Policy
Last updated: October 05, 2026
1. Our commitment
Protecting the data of those who trust herkul (CNPJ 63.640.519/0001-54) is part of how we build software. Below is a summary of the practices we use to protect information on our website and in the projects we deliver.
2. Infrastructure
We host our applications with established cloud providers whose facilities hold industry certifications such as ISO 27001 and SOC 2 and offer physical security and redundancy. We isolate environments to reduce the attack surface.
3. Encryption
All website traffic is served over HTTPS with current TLS. Sensitive data at rest is protected using the encryption features of our providers.
4. Access control
We follow the principle of least privilege: access to environments and data is limited to those who need it, with strong authentication and, where available, multi-factor authentication (MFA).
5. Dependencies and updates
We monitor the libraries we use and apply security fixes regularly, prioritizing known vulnerabilities.
6. Backups and continuity
We use backup routines for the projects we host to reduce the impact of failures and enable data recovery.
7. Responsible disclosure
If you discover a vulnerability in our systems, we appreciate responsible disclosure. Write to support@herkul.com.br with the details and give us a reasonable time to fix it before making it public.
herkul · CNPJ 63.640.519/0001-54