Snapshot 20979
Normalized text
Scripts and page chrome removed; this is what change detection compares.
← Trust Center Supplier and Subprocessor Management Version 1.0 Owner Founder Approved by Murilo Martins (Founder) · 09/28/2026 Next review 2027-09-28 (annual or on significant change) Scope Every third party that hosts, processes or can access SemantiqWall systems or data, and the software supply chain (open-source dependencies). 1. Supplier inventory Supplier Purpose Data it can access Location Status Hostinger VPS hosting (compute, disk, network, datacenter) All platform data, logs and backups Brazil (Campinas, São Paulo); ISO/IEC 27001:2022 certified (public statement); certificate and security documentation reviewed 2026-09-28 under Hostinger's confidentiality terms - the certified scope covers the VPS service we use Active - subprocessor Backblaze Off-site backup storage (B2, bucket with Object Lock) Encrypted backup packages only; it holds no key to open them United States (us-east) Active - subprocessor Resend Transactional e-mail (watch-list confirmation and vendor alerts) Recipient e-mail, name and message content Region sa-east-1 (São Paulo) Active - subprocessor GoDaddy (Titan Mail) Company mailbox [email protected] Messages sent to us (support, privacy and security requests) Mailbox server location not stated Active - subprocessor GitHub Private source code repository; deploy key; SemantiqWall GitHub App for customers who install it Our code; for App users, the files the customer allows and the pull requests we open United States Active - supplier; subprocessor only for GitHub App users Anthropic AI provider for optional case triage and remediation proposals Case summary and evidence text, agent description, up to 4 files of the customer's code United States Optional - used only when configured Meta (WhatsApp Cloud API) Optional approval messages Approver phone number, approval message Meta infrastructure Disabled Certificate authorities (ACME, via Caddy) TLS certificates Domain names only - Active GoDaddy (registrar) semantiqwall.com registration and DNS (renews 2027-09-27) DNS records - Active Open-source packages (Composer, npm) Application and SDK dependencies None at runtime beyond the code itself - Pinned in lock files The public list of subprocessors is kept in the privacy policy and updated before a new subprocessor starts receiving personal data. Customers can object by writing to [email protected]. 2. Shared responsibility with suppliers Area Supplier is responsible for SemantiqWall is responsible for Hosting (Hostinger) Datacenter physical and environmental security, hardware, hypervisor, network up to the VPS, media disposal Everything inside the VPS: OS hardening and updates, firewall, SSH, application, database, backups, encryption, monitoring E-mail (Resend, Titan) Delivery infrastructure and security of their platforms Account MFA, API key protection, content we send, domain authentication records Code hosting (GitHub) Platform security Repository access, MFA, deploy keys, App permissions (least privilege: contents, pull requests, metadata) AI provider Model hosting and their data handling commitments Sending only the minimum, treating output as untrusted, never letting AI decide allow/deny, turning the feature off if terms change 3. Selecting a new supplier Before a supplier receives customer or personal data, the Founder checks and records in the security register: purpose and the minimum data needed; security evidence - SOC 2 or ISO 27001 report or a public security page; data processing terms, including international transfer clauses when outside Brazil, breach notification and subprocessors; data location and retention; MFA available on the account; how to leave: export and deletion. A supplier handling customer data with no security evidence needs an exception (policy 00). 4. Requirements for suppliers Suppliers must keep customer data confidential, use it only to provide their service to SemantiqWall, notify us of breaches affecting our data, and delete it at the end of the service. For today's suppliers these obligations come from their standard online terms, which are accepted rather than negotiated. 5. Review Annually, and when a supplier changes its terms, location or ownership or has a breach: re-check section 3, confirm MFA on our account, and record the review. First formal review of Hostinger - done 2026-09-28: datacenter location confirmed (Campinas, Brazil) in the Hostinger panel; ISO/IEC 27001:2022 certificate, physical security, media disposal and business continuity documentation reviewed in Hostinger's Trust Center (obtained under its confidentiality terms and kept privately; the certified scope covers VPS hosting and includes physical security and secure disposal of storage media); MFA confirmed on all supplier accounts (policy 01). Commitment - rest of the first formal review: archive the data processing terms of Hostinger, Resend, GoDaddy, GitHub, Backblaze and Anthropic and review their security pages (owner: Founder, target 2026-10-31). Supplier incidents follow policy 05. 6. Software supply chain Dependencies are pinned (composer.lock, SDK lock files) and come only from official registries. The GitHub App requests only the permissions it needs, and SemantiqWall never merges pull requests in customers' repositories. Commitments: dependency alerts (target 2026-10-15), composer audit in CI and deploy (target 2026-11-30) and a Software Bill of Materials per release (target 2026-12-31), as set in policies 03 and 07.