Security

Security by design, with clinical governance.

How Radai Labs protects institutional and clinical data across its SaaS products.

Infrastructure

  • Hosting on major public-cloud providers with internationally certified data centers.
  • Production environments segregated per product (RadReport, RadVenture, ResiProva).
  • Logical per-tenant isolation and context-scoped keys.

Encryption

  • Modern TLS on all public interfaces.
  • Encryption at rest on managed databases.
  • Application secrets kept in managed vaults, never in source code.

Access control

  • Strong-password authentication with email verification and brute-force protection.
  • Least-privilege internal roles with periodic access reviews.
  • Audit logs for critical administrative operations.

Development lifecycle

  • Code review for every production change.
  • Continuous dependency updates and monitoring of known vulnerabilities.
  • Test environments segregated from real clinical data.

Incident response

In a personal-data security incident, Radai Labs notifies data subjects and the Brazilian data-protection authority (ANPD) within LGPD's timeframes and requirements.

Responsible disclosure

Found a potential vulnerability? Email contato@radailabs.com.br with subject Security — Responsible Disclosure. We do not take punitive action against good-faith researchers using this channel.

Security contact

Dr. Nailson Costa — DPO and security focal point at Radai Labs. Email: contato@radailabs.com.br.