Data Protection and Security

Vulnerability Management and Security Updates Policy

How vulnerabilities are identified, classified, prioritized, remediated, communicated and recorded.

Back to Compliance
Data Protection and SecurityIn effectReading time: 8 minutes
juridico@haborahub.com.br
Version
1.0
Published on
July 1, 2026
Last updated
July 1, 2026
Next scheduled review
July 1, 2027

1. Purpose

This Policy defines how vulnerabilities shall be identified, classified, prioritized, fixed and monitored.

2. Sources

Vulnerabilities may be identified through internal testing, dependency alerts, supplier reports, audits, log analysis, customers, researchers, incidents and monitoring.

3. Classification

Vulnerabilities may be classified as critical, high, medium, low or informational, according to impact, exposure and exploitability.

4. Prioritization

Prioritization shall consider risk to data, active exploitation, impact on customers, ease of exploitation, public exposure, financial impact and the existence of a fix.

5. Remediation

Remediation may involve updating dependencies, code changes, configuration adjustment, token revocation, access blocking, temporary mitigation or a definitive fix.

6. Communication

When there is relevant risk, HABORA may notify affected customers, data subjects or authorities, according to legal requirements and risk assessment.

7. Record

Relevant vulnerabilities must generate a record with date, severity, description, affected system, responsible party, status, action taken and fix date.

Contact

Questions, legal requests, privacy requests, formal communications and requests related to this policy should be sent to juridico@haborahub.com.br.

Updates

This policy may be revised to reflect legal, regulatory, technical, commercial or operational changes. The current version will remain available in the HABORA Compliance area. Material changes may require new acceptance by users, where applicable.

Related documents