Security
Last updated: February 20, 2026
Fixilify is built and operated by UNFOLDING THE FUTURE LTDA (UNFLD). Security is foundational to everything we build. We understand that connecting to your repositories requires the highest level of trust, and we take that responsibility seriously. This page outlines the measures we implement to protect your data, systems, and privacy.
1. Our Security Commitment
Fixilify is designed with a security-first architecture. Every component of our platform — from data ingestion to investigation analysis to report delivery — is built with multiple layers of protection. We continuously invest in security infrastructure, processes, and training to stay ahead of evolving threats.
2. Infrastructure Security
Our infrastructure is hosted on AWS, which holds SOC 2 Type II, ISO 27001, and PCI DSS Level 1 certifications for the platform layer. Key measures include:
- Fully isolated compute environments for each customer's investigation processing
- Network segmentation with strict firewall rules and intrusion detection systems
- Automated infrastructure provisioning with immutable deployments
- Real-time monitoring with automated alerting for anomalous activity
- Geographic redundancy across multiple availability zones for high availability
3. Data Encryption
All data is encrypted both in transit and at rest:
- In Transit: All communications use TLS 1.3 with strong cipher suites. We enforce HSTS and certificate pinning for API connections.
- At Rest: Data is encrypted using AES-256 encryption with customer-specific keys managed through a dedicated key management service.
- Repository Data: Code processed during investigations are encrypted with ephemeral keys and automatically purged after analysis unless explicitly retained by your configuration.
4. Access Controls
We enforce strict access controls across the platform:
- Role-based access control (RBAC) for all user accounts with configurable permission levels
- Multi-factor authentication (MFA) available for all users and required for administrative access
- Single sign-on (SSO) integration with major identity providers (Okta, Azure AD, Google Workspace)
- Principle of least privilege applied to all internal systems and employee access
- Comprehensive audit logs for all access events, configuration changes, and investigation activity
5. Application Security
Our development practices incorporate security at every stage:
- Secure Software Development Lifecycle (SSDLC) with mandatory security reviews for all code changes
- Automated static analysis (SAST) and dynamic analysis (DAST) in our CI/CD pipeline
- Regular dependency scanning and automated vulnerability patching
- Input validation, output encoding, and parameterized queries to prevent injection attacks
- Rate limiting, request throttling, and DDoS protection on all endpoints
6. Compliance
Fixilify is operated by UNFLD, and its compliance posture is governed at the UNFLD level rather than per product. The authoritative and continuously maintained detail — including control domains, policy documents, and the current status of each framework — is published here:
UNFLD Compliance
Full disclosures across our control domains, the information security policy governing them, and the current standing of every framework below are available at unfld.com.br/compliance.
In summary, the frameworks that apply to Fixilify are:
- ISO 27001 / 27002: Information security management system controls and review cadence maintained as UNFLD practice, on AWS-certified infrastructure
- SOC 2 Type II: Security, availability, and confidentiality criteria maintained as UNFLD practice, on AWS-certified infrastructure
- LGPD: Brazilian personal data protection across the products we operate, addressed contractually
- GDPR: Legal basis, data processing agreements with Standard Contractual Clauses, and data subject rights, addressed contractually
- NIS2: Aligned on risk management, incident reporting, and supply chain practice
- PCI DSS Level 1: Platform accreditation inherited from the hosting layer
Compliance documentation and reports are available to Enterprise customers on request.
7. Incident Response
We maintain a comprehensive incident response program:
- 24/7 security operations center (SOC) with automated threat detection and response
- Documented incident response procedures with defined escalation paths and response time targets
- Customer notification within 72 hours for any confirmed data breach affecting your information
- Post-incident reviews with root cause analysis and preventive measures shared with affected parties
- Regular tabletop exercises and incident response drills to maintain team readiness
8. Vulnerability Disclosure
We welcome responsible disclosure of security vulnerabilities. If you discover a potential security issue, please report it to our security team. We commit to:
- Acknowledging receipt of your report within 24 hours
- Providing regular updates on our investigation and remediation progress
- Not pursuing legal action against good-faith security researchers
- Crediting researchers (with permission) in our security acknowledgments
9. Employee Security
All Fixilify employees undergo rigorous security measures:
- Background checks for all employees with access to customer data or production systems
- Mandatory security awareness training upon onboarding and quarterly refreshers
- Encrypted, company-managed devices with endpoint detection and response (EDR)
- Access revocation procedures executed within 1 hour of employment termination
10. Data Isolation
Customer data is strictly isolated at every level:
- Logical data separation with unique encryption keys per customer
- Dedicated compute environments for investigation processing — your code is never co-processed with another customer's data
- Codebase connection tokens are securely stored with hardware security module (HSM) backing
- Investigation data is ephemeral by default and automatically purged after report generation unless retention is configured
11. Contact Our Security Team
For security inquiries, vulnerability reports, or to request our compliance documentation, please contact us. Our full compliance disclosures are published at unfld.com.br/compliance.