Information security policy
The principles and measures with which we protect the information of our customers and their contacts.
Last updated: 24 September 2026
Management commitment
The management of Tarraconsulting International S.L. considers information security an essential element in providing the Exporta.ai service and in earning the trust of its customers. It therefore approves this policy, allocates the resources needed to apply it and commits to its continual improvement. The policy draws on the good practices of the ISO/IEC 27001 standard and on the requirements of the General Data Protection Regulation.
Scope
It applies to the Exporta.ai platform (application, API, MCP server and website), to the information it processes and to all persons (employees, collaborators and providers) who access it.
Principles
• Confidentiality: information is accessible only to those who are authorised. • Integrity: information is accurate and complete and is only modified in an authorised manner. • Availability: information and the service are accessible when needed. • Traceability: relevant actions are logged and can be attributed to whoever performed them. • Least privilege and data protection by design and by default.
Organisation and responsibilities
Management bears ultimate responsibility for information security. It appoints a security officer who coordinates the application of this policy, risk management and incident response. All persons with access to the information must be familiar with this policy, comply with it and report any incident.
Risk management
We identify and assess the risks to the information and the service, and apply measures proportionate to them. We review them when the platform, the providers or the threat landscape change.
Isolation and access control
• Each customer's data are isolated: every query is filtered by organisation in the application, and the database applies row-level security policies as a second barrier. • Users can enable two-step verification (TOTP), and each account has roles with different permissions. • The internal administration panel is accessible only to authorised staff, from a separate domain, with mandatory two-step verification. • Staff do not access the content of customer accounts except to provide support, with a recorded reason, on a temporary basis (30 minutes) and leaving a record in the audit log. • API keys and assistant access tokens (OAuth with PKCE) are stored only as encrypted fingerprints (hashes), are revocable and expire.
Information protection
• All communications are encrypted in transit (HTTPS/TLS, with HSTS). • Data are hosted in the European Union (Ireland) with infrastructure providers that encrypt stored information. • Files are kept in private storage and are served only through short-lived signed links. • Passwords are managed by the authentication provider and are never stored in plain text. • Service secrets and credentials are kept outside the code, in protected environment variables.
Operations and development security
• Every code change goes through automated tests, static analysis and type checking before it is deployed. • The application applies security headers, protection against requests to internal networks (SSRF), signature verification on payment notifications and per-customer usage limits to prevent abuse. • We log access and relevant operations with request identifiers, and keep audit logs for the periods stated in the Privacy policy. • We monitor platform errors in order to detect and correct incidents.
Providers
We select providers that offer adequate security and data protection guarantees, sign the corresponding data processing agreements with them and periodically review those that process our customers' information. The list is set out in the Data processing agreement.
Incident management
We have a procedure to detect, contain, analyse and resolve security incidents. If an incident affects personal data, we notify the affected customers within 48 hours at most and, where appropriate, the Spanish Data Protection Agency, Agencia Española de Protección de Datos (AEPD), within 72 hours at most, and we document the measures taken.
Continuity
The platform relies on managed services with high availability and database backups, and is designed so that a failure of an external provider does not cause data loss or undue charges: actions that fail automatically refund their credits.
Training and awareness
All persons with access to the information receive training on their security and confidentiality obligations, and are bound by a confidentiality undertaking.
Review
This policy is reviewed at least once a year and whenever significant changes occur. The version in force is the one published on this page. If you detect a possible vulnerability, write to us at hola@exporta.ai with the subject "Security". We appreciate responsible disclosures and will handle them as a priority.