Security
Security by design, with clinical governance.
How Radai Labs protects institutional and clinical data across its SaaS products.
Infrastructure
- Hosting on major public-cloud providers with internationally certified data centers.
- Production environments segregated per product (RadReport, RadVenture, ResiProva).
- Logical per-tenant isolation and context-scoped keys.
Encryption
- Modern TLS on all public interfaces.
- Encryption at rest on managed databases.
- Application secrets kept in managed vaults, never in source code.
Access control
- Strong-password authentication with email verification and brute-force protection.
- Least-privilege internal roles with periodic access reviews.
- Audit logs for critical administrative operations.
Development lifecycle
- Code review for every production change.
- Continuous dependency updates and monitoring of known vulnerabilities.
- Test environments segregated from real clinical data.
Incident response
In a personal-data security incident, Radai Labs notifies data subjects and the Brazilian data-protection authority (ANPD) within LGPD's timeframes and requirements.
Responsible disclosure
Found a potential vulnerability? Email contato@radailabs.com.br with subject Security — Responsible Disclosure. We do not take punitive action against good-faith researchers using this channel.
Security contact
Dr. Nailson Costa — DPO and security focal point at Radai Labs. Email: contato@radailabs.com.br.