Security
Devx builds products that handle business data — including financial data. This page describes, without exaggeration, how we protect that data today, who helps us run our services and how to report a vulnerability.
We don't have formal certifications yet (such as SOC 2 or ISO 27001). When we do, they will appear here.
Products covered by this page
Companies that process data on our behalf to run the site and the products above. Payment gateways that a customer business connects with its own account in FinSight AI are not Devx sub-processors: the contract is directly between the business and the gateway. Changes to this list are published here.
| Company | Purpose | Data processed | Location | Used in |
|---|---|---|---|---|
| Hostinger | Hosting server (VPS) and site email | Data processed by the application and email messages | Brazil | Site and FinSight AI |
| Supabase | Managed database | Account data and product content | Brazil (São Paulo) | Site and FinSight AI |
| Cloudflare | DNS, content delivery, firewall and bot verification | IP address and technical request data | Global | Site and FinSight AI |
| Sign in with Google, AI (Gemini) and usage analytics with consent | Sign-in data; text sent to the AI, with personal data masked; browsing data | Global | FinSight AI | |
| GitHub | Sign in with GitHub | Sign-in data | United States | FinSight AI |
| OpenAI | AI, when enabled | Text sent to the AI, with personal data masked | United States | FinSight AI |
| Mercado Pago | Billing for platform subscriptions | Payment and billing data | Brazil | FinSight AI |
| Asaas | Billing for subscriptions (card and Pix Automático) | Payment and billing data | Brazil | FinSight AI |
| Pluggy | Bank connections via Open Finance | Bank data authorized by the customer | Brazil | FinSight AI |
| Focus NFe | Service invoice issuance, when used | Invoice data | Brazil | FinSight AI |
| Meta (WhatsApp Business) | Billing reminders on WhatsApp, when enabled | Name, phone number and billing data | Global | FinSight AI |
Found a vulnerability? Write to the email below with the steps to reproduce it. We ask that you:
We reply as quickly as possible and won't take legal action against anyone acting in good faith within these rules. We don't have a bug bounty program yet. The same contact is in our security.txt.