Security Self Assessment
Versão: Março de 2023
Histórico do documento
Data | Descrição | Autor | Revisores |
---|---|---|---|
Março de 2023 | Atulizar data ultimo Pentest | JHS | RAT |
Fevereiro de 2023 | Inclusão novas questões | JHS | RAT |
Março de 2021 | Inclusão novas questões | JHS | SIBS, RAT |
Self Assessment - Security Questionnaire
Name of Company: Woovi / Woovi LLC
Applications: In scope for this Security Questionnaire
Woovi is a instant payment provider
Primary Contact for Security
Name: Infosec Team
Email: security (at) woovi.com
Secondary Contact for Security
Name: Sibelius Seraphini
Job Title: CTO
Email: sibelius (at) woovi.com
Tertiary Contact for Security
Name: Rafael Turk
Job Title: CoFounder
Email: rafael (at) woovi.com
Company Information
Question | Comments |
---|---|
Geographic Country location of employees, including contractors with access to production infrastructure and applications | Brazil |
Company Certifications and Accreditations e.g. ISO, SAS-70, PCI DSS, HIPAA or other | Certification is in progress expected for 4Q |
Regulatory compliance requirements and industry standards | Brazil LGDP |
Data Center Information | AWS |
Data Center Country Location | GRU - AWS GRU - São Paulo Region |
Who is responsible for the data center facility? | Cloud based, AWS |
Who is responsible for system administration? Also, note any Third party companies for Data Center Hosting and Operations | Woovi |
Any Third party companies have access to Data Center Hosting and Operations? | No. Restricted to Woovi |
Give details of the facility’s data center security and business continuity resources e.g. closed room, physical access controls, card reader, video surveillance, power, cooling, etc. | AWS managed |
Security Practices In your solution do you test for OWASP and other vulnerabilities? | Yes. |
Product information
Question | Comments |
---|---|
Does your solution involve PII/Sensitive data originating from Cloud Software as a Service (SaaS)? | Yes. |
The platform may use Customer data originating from Cloud Services (Saas) to authorize payments transactions? | Yes. This is a core feature of the platform |
Does your solution store retrieve PII/Sensitive data in Cloud Services (SaaS, PaaS)? | Yes. Ecommerce plugins may pass Customer Name and TaxID to enrich payment information |
Gateway may use Customer data originating from Cloud Services (Saas) to authorize payments transactions. | Yes. |
Does your solution retrieve PII/Sensitive data from on-premise applications? | N/A Our platform don't have any onpremisse solutions. |
Gateway may use Customer data originating from Cloud Services (Saas) to authorize payments transactions. | Yes. |
Do you have a mobile application that persists PII/Sensitive data on the device? | N/A. Our platform don't use any kind of Mobile Apps. |