Information Security

Your Data Secure, Your Business Protected.

At NEXO, information security is treated as a fundamental requirement.

Our solutions are developed with a strong focus on protecting sensitive data, especially in the context of Occupational Health and Safety (OHS), serving companies of all sizes and industries.

LGPD — Compliance with Data Protection Legislation

The General Data Protection Law (LGPD) establishes rules for the collection, processing, storage, and sharing of personal data in Brazil, aiming to ensure individuals' privacy and promote transparency in the use of information.

LGPD Compliance

NEXO is fully compliant with the principles of the LGPD. All operations involving personal data on our platforms follow legal criteria such as purpose, necessity, consent, and accountability. The company maintains processes and controls to ensure ongoing adherence to the legislation.

ISO 27001 — Information Security Certification

ISO/IEC 27001 is an international standard for information security management, defining best practices to protect data from leaks, loss, or unauthorized access.

NEXO ISO 27001 Certification

NEXO is ISO 27001 certified. This certification recognizes that the company adopts formal information security processes and maintains controls aligned with the standard’s requirements. This includes internal policies, access control, risk management, and incident response.

Security in Architecture and Operations

NEXO solutions are implemented with robust technical security measures, including:

  • Encryption in transit and at rest
  • Role-Based Access Control (RBAC)
  • Activity logging and auditing
  • Automated backups with defined retention policies
  • Vulnerability and event monitoring

ISO and Certifications

At NEXO, we are committed to quality, safety, and excellence in our solutions.

That’s why we hold a range of certifications and follow strict standards that demonstrate our commitment.

NEXO is ISO 27001 certified, an international standard that defines requirements for an Information Security Management System (ISMS). This certification ensures that we adopt best practices to protect sensitive information, mitigating risks such as data loss, unauthorized access, and privacy breaches. In addition, NEXO follows strict security standards, with regular audits to ensure the effectiveness of the measures in place.

Our company’s cloud environment is supported by Microsoft Azure infrastructure, which adheres to the most rigorous international standards for security, privacy, and compliance, including:

CSA STAR Level 2:

Record of cloud security best practices

FedRAMP High / Moderate:

For U.S. government clients

GDPR e LGPD readiness:

Framework for compliance with data protection laws

ISO/IEC 20000-1:

IT Service Management

ISO/IEC 22301:

Business continuity (applicable to managed environments and critical services)

ISO/IEC 27001:

Information Security Management

ISO/IEC 27017:

Specific controls for cloud services

ISO/IEC 27018:

Protection of personal data (PII) in the cloud

PCI DSS:

For services applicable to payment card data

SOC 1 Type II:

Internal controls over financial reporting and data security, confidentiality, and integrity.

SOC 2 Type II:

Internal controls over financial reporting and data security, confidentiality, and integrity.

Commitment to Quality and Excellence

Our certifications are a clear demonstration of our commitment to quality and excellence. Here are some of the benefits that our NEXO solution offers, reflecting our ongoing dedication.

With these certifications and practices, NEXO stands out in the market as a reliable company committed to excellence, providing peace of mind and security to its clients.

24/7 Monitoring

Monitored system ensuring uninterrupted operation.

24/7 Availability

Solutions always available, without interruptions.

Redundancy and Backup

Data protection with backups and redundancy.

Secure Environment

Continuous security and protection of information.

Questions about Information Security?

Talk to our team and learn how we protect the data processed in our solutions.