Security built for real operation
How we protect data and access day to day: isolation between organizations, control over who can do what, a record of what happened, and human approval for the actions that matter most.
How we protect the operation
Six areas that sustain data isolation, access control, and service continuity.
Isolation between organizations
Each organization accesses only its own data. Isolation is enforced at the data layer, not just the interface.
- Per-organization access rules enforced directly at the database.
- No customer query reaches another customer’s data by default.
Authentication and permissions
Control over who logs in and what each role can do inside the platform.
- Secure session login with lockout after failed attempts.
- Role-based permissions — each user only sees and does what their role allows.
Logging and auditing
Relevant actions are logged, with identifiable origin and owner.
- Audit trail for administrative and critical actions.
- Traceability of what was done, by whom, and when.
Human approval for critical actions
Automation and AI speed up work, but don’t decide alone on what’s irreversible.
- Critical AI actions go through human approval before executing (human-in-the-loop).
- Documented AI governance, with oversight at the points that matter most.
Continuity and backups
Routines to reduce the impact of failures and enable recovery.
- Regular backups of operational data.
- Continuity plans for the most critical services.
Incident response and vendors
A process to handle security issues and evaluate who has access to our operation.
- Internal security incident response process.
- Evaluation of critical vendors before integrating them into the operation.
Governance & trust
Governance
How Centriu organizes itself to operate responsibly.
OpenPrivacy Policy
How we handle and protect personal data.
OpenStandards alignment
Alignment with ISO 27001, 27701, 20000-1, 42001 and 37001.
OpenPlatform status
Platform availability and operation.
OpenReport a security issue: integridade@centriu.com. Reports are handled confidentially.
Legal notice: the security practices described on this page represent real operational controls in effect at Centriu. They do not constitute a guarantee of absolute security, absence of risk, or continuous availability, and do not replace the customer’s own technical assessment. Centriu does not claim information security certification; any alignment with international standards is addressed on the Governance and Standards Alignment pages, always as operational alignment — not certification granted by an accredited body.
