Secure Development Policy – Secure SDLC
Secure development guidelines that govern new features, fixes, integrations and the evolution of the platform.
- Version
- 1.0
- Published on
- July 1, 2026
- Last updated
- July 1, 2026
- Next scheduled review
- July 1, 2027
1. Purpose
This Policy defines HABORA's secure development guidelines, governing new features, fixes, integrations and the evolution of the platform.
2. Principles
Development must consider security by design, privacy by design, least privilege, input validation, access control, data protection, review, testing and documentation.
3. Requirements
New features must assess the data processed, permissions, logs, LGPD impact, AI risks, financial matters, documents, integrations, database, users and properties.
4. Environments
Whenever possible, there must be separate development, testing, staging and production environments. Real data must not be used in tests without adequate protection or anonymization.
5. Review
Changes to authentication, permissions, database, documents, financials, AI, logs, payments and security must undergo technical and functional review.
6. Secrets
Credentials, tokens, API keys and passwords must not be placed in source code. They must be protected by environment variables, secret vaults or equivalent mechanisms.
7. Dependencies
Libraries and packages must be monitored and updated according to risk and stability.
8. Fixes
Vulnerabilities must be prioritized by severity, exposure, impact and exploitability.
Contact
Questions, legal requests, privacy requests, formal communications and requests related to this policy should be sent to juridico@haborahub.com.br.
Updates
This policy may be revised to reflect legal, regulatory, technical, commercial or operational changes. The current version will remain available in the HABORA Compliance area. Material changes may require new acceptance by users, where applicable.