Security is a first-class engineering concern at S.R. IMPULSO DIGITAL S.A.S.. This document summarizes the technical, organizational and operational controls we apply to protect the data of our clients and visitors. We continuously update these practices in line with industry standards.
1. Encryption in Transit
All data exchanged with our public website, APIs, dashboards and conversational endpoints is encrypted in transit using TLS 1.2 or higher (TLS 1.3 preferred). HSTS is enforced. Insecure ciphers and protocols (SSLv3, TLS 1.0/1.1) are disabled.
2. Encryption at Rest
Production data is encrypted at rest using AES-256 (or stronger equivalents) on managed cloud storage and databases. Keys are managed by our cloud providers' Key Management Services with periodic rotation.
3. Cloud Infrastructure
Impulso Digital operates on hyperscale cloud providers (e.g. AWS, Google Cloud, Cloudflare) selected for their compliance posture (SOC 2, ISO 27001). Workloads run in segmented virtual private networks, with infrastructure-as-code configurations under version control and peer review.
We follow the principle of least privilege for service-to-service communication, and isolate environments (development, staging, production) so that no production data ever flows downstream.
4. Authentication and Access Control
Access to privileged systems requires multi-factor authentication (MFA). Role-based access control (RBAC) ensures team members only access the data needed to perform their role. Joiner/mover/leaver procedures are enforced, and access reviews are conducted periodically.
5. Network Security
Public endpoints are protected by managed Web Application Firewalls (WAF), DDoS mitigation and rate limiting. Internal services are not exposed to the public internet. Bastion / just-in-time access is required for administrative operations.
6. Monitoring and Logging
Authentication events, configuration changes and abnormal activity are logged and monitored. Alerts trigger on suspicious behaviour. Logs are retained securely for forensic and compliance purposes.
7. Backups and Disaster Recovery
Production data is backed up automatically on a recurring schedule with encryption and integrity checks. Restore procedures are tested. Our target recovery point and recovery time objectives are defined in client engagements.
8. Vendor Risk Management
Every sub-processor that handles client or personal data is evaluated for security, privacy and operational maturity, and is bound by a written Data Processing Agreement (DPA).
9. Secure Development
Code is developed under version control with mandatory peer review. Dependencies are scanned for known vulnerabilities. Secrets are kept out of source code and managed via vault services. AI models and prompts are reviewed for prompt-injection and data-leakage risks.
10. Incident Response
We maintain a documented incident-response plan. In the event of a confirmed security incident affecting your data, we will notify you without undue delay and in any case within the timeframes required by applicable law. To report a suspected incident or vulnerability, contact security@impuldigital.pro.
11. Responsible Disclosure
We welcome reports from security researchers. Please contact us before publicly disclosing any vulnerability so we have a reasonable window to remediate. We commit to acknowledging valid reports and crediting researchers who follow responsible disclosure.
12. Contact
Security team: security@impuldigital.pro
S.R. IMPULSO DIGITAL S.A.S. · NIT 1121923719
Cll 35b # 15a-45 Este, Manzana A Casa 14, Prados de Siberia, Villavicencio, Meta, Colombia