English Fale conosco →
Início / Políticas / Divulgações de segurança
Divulgações de segurança

Divulgações de segurança.

Nossa postura de segurança em linguagem clara: controles, certificações e como reportar uma vulnerabilidade.

Vigente · 1 May 2026 Versão · 3.2 Aplica-se a · lenscorp.ai e todos os produtos LENS Idiomas · Português (resumo) · Inglês (canônico)
Nota de tradução

Os resumos, navegação e metadados das políticas estão localizados. O corpo jurídico completo usa como fallback o texto canônico em inglês, exceto quando já mantemos uma versão traduzida específica.

01Security posture

LENS builds and operates AI products for cities, enterprises and critical infrastructure. We treat security as a precondition for that work, not a feature. Our posture is published, our claims are auditable, and our controls are designed for customer review.

02Certifications & audits

StandardStatusLast assessment
ISO/IEC 27001:2022CertifiedHeld in the OEM legal name
ISO 9001:2015CertifiedHeld in the OEM legal name
ISO 14001:2015CertifiedHeld in the OEM legal name
NIST CSF 2.0Self-assessedInternal review
HIPAA Security RuleAligned (BAA-ready)Continuous

Reports under NDA: solutions@lenscorp.ai.

03Selected controls

Encryption

TLS 1.2+ in transit (TLS 1.3 preferred). AES-256 at rest using FIPS-validated cryptographic modules. Key custody via the managed key service of the deployment cloud, with annual rotation.

Access

SSO with hardware MFA for production. JIT elevation with reviewer approval. Quarterly access reviews. No standing root access.

Logging

Immutable audit logs for every production action. 1-year hot retention; 6-year cold retention for PHI/regulated workloads.

Network

Zero-trust internal model: every service-to-service call is mutually authenticated. Public ingress is terminated with TLS.

SDLC

Required code review by a second engineer. Static analysis and dependency scanning on every pull request. Dependency upgrade targets: 7 days for high severity, 30 days for medium.

Incident response

24×7 on-call. Page-tested every quarter. Customer notification within 72 hours of confirmed incident; 5 business days for HIPAA Breach.

04Vulnerability disclosure

Found something? We want to hear from you. We commit to:

  • Acknowledging your report within 5 business days.
  • Giving you a triage outcome within 15 business days.
  • Not pursuing legal action against good-faith researchers operating under this policy.

Scope

In scope: *.lenscorp.ai and LENS-operated demo endpoints. Out of scope: customer-operated deployments (contact the customer), social engineering, physical attacks, denial of service.

How to report

Email solutions@lenscorp.ai with the affected URL, reproduction steps and impact. If you need to send the report encrypted, ask us for a key first and we will arrange it.

05Bug bounty

We do not currently run a paid bug bounty programme. Valid, novel reports are acknowledged and, with your permission, credited when we publish the fix. Duplicate and out-of-scope reports are not eligible for credit. To coordinate disclosure, email solutions@lenscorp.ai.

06Contact

Precisa de um aviso regional?

Publicamos avisos complementares para Índia, UE/Reino Unido, saúde nos EUA, Califórnia e Brasil.

Ver todas as políticas