Version: 1.0 | Effective: January 2026 | Updated: January 2026
π‘οΈ Security Policy
TodoHub
Protecting your data with robust technical and organizational measures
Our Security Commitment
Data security is a fundamental priority. We implement robust measures to protect your information against unauthorized access, loss, or alteration.
1. Security Principles
| Pillar | Implementation |
|---|
| π Confidentiality | Access restricted to authorized persons |
| π‘οΈ Integrity | Data protected against changes |
| ποΈ Availability | Service accessible when needed |
| π Privacy by Design | Security from conception |
| β‘ Least Privilege | Minimum necessary access |
2. Infrastructure
2.1 Cloud Providers
| Provider | Function | Certifications |
|---|
| AWS | Main infrastructure | SOC 1/2/3, ISO 27001, PCI-DSS |
| Google Cloud | Specific services | SOC 1/2/3, ISO 27001 |
| Firebase | Authentication & DB | SOC 2, ISO 27001 |
2.2 Data Location
| Users | Primary Region |
|---|
| π§π· Brazil | SΓ£o Paulo (AWS sa-east-1) |
| πͺπΊ Europe | Frankfurt (AWS eu-central-1) |
| πΊπΈ North America | N. Virginia (us-east-1) |
3. Encryption
3.1 In Transit
| Technology | Application |
|---|
| TLS 1.3 | All communications |
| HTTPS | Required for all connections |
| Certificate Pinning | Mobile apps |
| HSTS | Force secure connections |
3.2 At Rest
| Technology | Application |
|---|
| AES-256 | Sensitive data |
| bcrypt/Argon2 | Passwords (hashing) |
| Disk encryption | All servers |
| AWS KMS | Key management |
4. Authentication & Access
4.1 Authentication Methods
| Method | Availability |
|---|
| Email + Password | Standard |
| Google Sign-In | OAuth 2.0 |
| Apple Sign-In | OAuth 2.0 |
| Facebook Login | OAuth 2.0 |
| MFA/2FA | Optional (recommended) |
4.2 Password Requirements
- Minimum 8 characters
- Letters + numbers combination
- Cannot repeat last 5 passwords
- Lockout after 5 failed attempts
5. Network & Application Security
| Measure | Description |
|---|
| Firewall (WAF) | Web Application Firewall |
| DDoS Protection | AWS Shield / Cloudflare |
| OWASP Top 10 | All vulnerabilities mitigated |
| Input Validation | Strict input validation |
| SQL Injection | Parameterized queries |
| XSS Prevention | Output escape, CSP |
6. Backup & Recovery
| Type | Frequency | Retention |
|---|
| Incremental | Hourly | 24 hours |
| Daily | Daily | 30 days |
| Weekly | Weekly | 12 weeks |
| Monthly | Monthly | 12 months |
6.1 Characteristics
- Encryption: AES-256 on all backups
- Geo-redundancy: Separate region
- Testing: Monthly restoration tests
- RTO: 4 hours (Recovery Time Objective)
- RPO: 1 hour (Recovery Point Objective)
7. Monitoring & Response
7.1 24/7 Monitoring
| Category | Monitoring |
|---|
| Performance | Latency, throughput, availability |
| Security | Access attempts, anomalies |
| Errors | Exceptions, failures, crashes |
| Infrastructure | CPU, memory, disk, network |
7.2 Incident Response
| Level | Response |
|---|
| Critical | Immediate (24/7) |
| High | < 1 hour |
| Medium | < 4 hours |
| Low | Next business day |
8. Your Responsibilities
Security is a shared responsibility. You should:
- β
Use strong and unique passwords
- β
Enable two-factor authentication
- β
Not share credentials
- β
Log out on shared devices
- β
Keep devices updated
- β
Report suspicious activities
8.1 Report Vulnerabilities
If you discover a vulnerability, contact:
| Region | Contact |
|---|
| Global | security@todohub.com |
Β© 2026 TodoHub - All rights reserved
Document generated in January 2026 - Version 1.0