Data Protection and Confidentiality

Certified Safety, Guaranteed Trust

The security of your information is a priority at Artificial Nerds.

ISO/IEC 27001

The ISO/IEC 27001 standard helps manage Information Security in organizations, with processes to continuously improve it and control risks.

NYCE

Standardization and Certification NYCE, S.C., certification body accredited with the number 02/17, by the Mexican Accreditation Entity A.C. (ema)

IQNET

IQNET is a non-profit network with more than 30 years of experience, bringing together more than 40 certification bodies to evaluate quality, social responsibility and ICT in companies.

Our Certification

Artificial Nerds has a certificate ISO/IEC 27001:2013, which provides a strong information security system, ensuring that a Information Security Management System (SGSI) robust and ensures that rigorous measures are implemented to protect the confidentiality, integrity and availability of information, reducing the risk of data leaks and unauthorized access. In addition, it promotes continuous improvement in its security practices.

Customer Benefits

Peace of mind at all times ensuring the security and continuity of the service.

The confidence that their Data They are Protected against threats and vulnerabilities.

Clear and up-to-date documentation about their security policies and procedures, providing greater transparency about how their data is managed and protected.

Artificial Nerds' Reputation as a reliable and secure partner, which can translate into greater customer loyalty and satisfaction.

Confidentiality agreements with well-defined responsibilities.

Risk is minimized of security breaches and unauthorized access.

Privacy and Data Protection

The improvements implemented are aligned with various privacy and data protection regulations, such as the Federal Act for the Protection of Personal Data Held by Individuals and other local laws, assuring customers that their data is being managed in accordance with the law.

Planning and Ongoing Security

We train our team in security and emergency response. We have a Disaster Restoration Plan (DRP), continuity tests, Ethical Hacking and audits, reviewed periodically to ensure the protection and continuous operation of our services.

Our Security

Redundancy

We maintain encrypted backups in multiple geographic locations. This ensures that, in the event of a failure in one location, data can be quickly restored from another.

Monitoring

We implement advanced monitoring systems to detect and respond to incidents in real time. Our security team is available 24/7 to address any potential threat.

Risks

We conduct regular risk assessments and treatment to identify and address potential threats to information security.

Authentication

We have implemented strict policies for password and key management, with complexity requirements, regular changes and management tools. We also use multi-factor authentication in all of our critical systems for added security.

Secure development

Our secure development practice includes code reviews, automated and manual security testing, and the adoption of secure coding principles. By ensuring that our code is free of known vulnerabilities and following secure development best practices, we protect our applications against potential attacks.

Policies

We maintain documented, clear and updated security policies that are communicated to all employees. These policies cover all aspects of information security, from access management to data protection and incident response.

SSL certificate

Provided by DigiCert, one of the leaders in the digital security industry, it guarantees the protection of data transmitted between the server and users through strong encryption, preventing unauthorized access and attacks by intermediaries, increasing trust and promoting a more secure user experience.

Communication

Use of encrypted and secure internal communication platforms to share sensitive information, minimizing the risk of unauthorized access. In addition to information transfer policies for the control and segregation of information.

Infrastructure

Artificial Nerds works with what are AWS and GCP. All data is encrypted both in transit and at rest. The data is stored in encrypted form in our databases using the AES encryption method, as well as in transit with SSL/TLS. A backup management policy and procedure for managing public and private keys are also implemented.

Data Encryption

The security implemented for the protection of personally identifiable data is general and consistent for all company information, regardless of whether or not it contains personal data. Ensuring that integrity, confidentiality and availability are permeated in the personal data it manages. Artificial Nerds uses AES encryption for the protection of personal data

Provider

Our main specialized vendor providing support for the implementation and maintenance of the SGSI is Hackmetrix.

Secure payments

Our chatbots are transactional, for which we use secure payment links thanks to our BP Getnet/ Santander. Gateway with 3D Secure.

Partners and Providers

We have leading international suppliers that ensure the confidentiality, integrity and availability of the information processed by Artificial Nerds

Google Cloud Provider

WhatsApp Business Partner

AWS Partner Network

Meta Business Partner

MIT

Santander

Hackmetrix

Cívica Digital