WardizonWARDIZON
Trust & Security

Security isn’t a feature.
It’s the whole product.

You’re selling security to your clients. We hold ourselves to the standard that demands: tenant isolation, encrypted credentials and client-signed consent built into the foundation, not bolted on.

ISOLATION
Every client in its own tenant

Wardizon is multi-tenant by design. Each client has its own tenant, and the database enforces row-level security on every console and API request, so one client’s records are not visible from another client’s account.

ENCRYPTION
Credentials locked down

Credentials your client supplies for authenticated testing are encrypted at rest, under a key kept outside the database, and are tied to the signed scope they were given for. All traffic to the platform runs over HTTPS.

WHERE DATA LIVES
Hosted in Brazil

The platform and your clients’ data are hosted on a server in Brazil, and backups are taken on business days to a Brazilian data center. AI-assisted analysis sends finding details to Anthropic in the USA. The main vendors that process data for us, and where they run, are listed below.

AUTHORIZATION
No scan without consent

No test starts until your client signs the Rules of Engagement (RoE) online. You initiate it, your client authorizes it, and Wardizon never authorizes or starts a test on its own. The signed record keeps who signed, their title and email, when, and the exact scope they approved.

ACTIVE TESTING
Consent before impact

Wardizon tests actively. Some checks send requests that can change data in the application under test, such as submitting a test value to confirm a business-logic flaw, and any active test carries some risk to fragile systems. That is why the scope is written into the RoE and your client signs it before anything runs.

Compliance mapping

Mapped to your clients’ frameworks.

Findings are mapped to the frameworks your clients answer to: control coverage for PCI DSS, NIST 800-53, ISO 27001 and HIPAA, readiness evidence for SOC 2, and risk posture for LGPD and GDPR. It gives their audit work a starting point. Here’s how the platform itself is built.

PCI DSSNIST 800-53ISO 27001SOC 2HIPAALGPDGDPR
Row-level tenant isolationOn
Client-signed RoE before any testRequired
Stored credentialsEncrypted
Backups (Acronis, Brazil)Business days
SUBPROCESSORS

The vendors that process data for us, what each one does, and where. The Pentest Intelligence Engine is ours; for AI-assisted analysis it sends finding details, such as the target, evidence excerpts and the client’s name, to Anthropic (Claude) in the USA.

HostingerPlatform hosting · Brazil
AcronisBackups · Brazil
Anthropic (Claude)AI-assisted analysis · USA
CloudflareDNS and proxy · Global
Microsoft 365Email
StripePayments
SplunkInfrastructure monitoring · USA
VercelWebsite hosting · USA
SupabaseWebsite forms · Brazil
HubSpotCRM · USA
Customer.ioEmail platform · USA
RESPONSIBLE DISCLOSURE

Found a vulnerability in Wardizon itself? We want to hear from you. Report it privately and we aim to acknowledge within 2 business days, keep you posted through the fix, and credit you if you’d like.

support@wardizon.com
Questions about security or a vendor review? contato@wardizon.com