Security

The Platform was designed so that data stays under the government institution's ownership and control at all times, with security and privacy, in a transparent environment and in compliance with Brazil's LGPD.

Under Brazil's LGPD the contracting party, always a government public security institution, is the data controller, Pax is the processor and the citizen is the data subject. Pax processes data only on the contracting party's instructions and does not decide how it is used.

01data ownership and access

Operated by Pax, held by the government, owned by the citizen

Clear ownership and jurisdictional control

  • Data is stored and processed securely inside the country, meeting data residency requirements and staying under Brazilian law.

No commercialisation

  • Ownership and control of citizens' data stay entirely with the government institution: Pax never collects, sells or repurposes any data.

Two kinds of data, neither of them Pax's

  • Citizens' data and government institution data: The Platform handles citizens' data and the government institution's data, but Pax neither controls nor owns any of it.
  • Pax's role: Pax acts only as the provider of the processing tool: it does not own the data and has no free access to it. Use is restricted to previously credentialed public security professionals.

Retention

  • Retention and deletion: Retention and deletion rules are set by the government institution, ensuring citizens' data is kept only as long as required.
  • Irreversible deletion: At the end of the retention period, data is purged from the Platform, permanently and irreversibly.
02transparency and traceability

A complete, unalterable trace

Unalterable records of platform actions

  • No edits, no deletions: Every action on the Platform writes an audit record that can only be created: never edited, never deleted.
  • Identity and timestamp metadata: Traceability of access and queries is preserved in full: the government institution can reconstruct which officer accessed which data, and when.
  • A barrier against abuse: Instead of opening a door to abuse, the technology creates a trail of accountability: public oversight, traceability, and a concrete barrier against leaks.

The principle of least privilege

  • Permissions are set by role and by attribute. Each user sees only the records and fields their role requires, and the rest stays hidden.

Purpose-bound data sessions

  • Require explicit, purpose-bound access to sensitive data by enforcing just-in-time justification at the moment of use, with every access logged alongside full contextual metadata for audit and review.

Encryption at rest and in transit

  • At rest: Data encrypted with AES-256.
  • In transit: All traffic crossing the public internet requires TLS 1.2 or higher.
  • Key management: Keys are managed in a service separate from the application, with their use and lifecycle defined by policy.

Secure authentication and authorisation

  • Multi-factor authentication is required for access to critical systems and protects officers' credentials, so that a compromised credential is not enough on its own to reach citizens' data.

Continuity and data integrity

  • Redundant copies: The data modules keep redundant backups, so an infrastructure failure does not mean losing police records.
  • 24/7 monitoring: Infrastructure is monitored 24 hours a day, seven days a week, with automated alerts routed to an on-call team. An anomaly is caught at any hour, not only during business hours.
04responsible AI

AI under human control

AI that complements human judgement

  • A person always decides: The Platform's AI is assistive: it organises and presents evidence, it never decides. Every critical decision stays with the public official, who decides from the evidence presented.
  • Deterministic guardrails: Where precision is required, AI behaviour is constrained by defined business and policy rules, so that outputs stay predictable, auditable and aligned with operational intent.

AI that is controlled, explainable and traceable

  • Interpretable outputs: AI outputs are never presented without an explanation: the user sees the reasoning and the supporting evidence, not only the result.
  • End-to-end provenance: Every AI output carries the full lineage of what produced it, linking directly back to the underlying evidence, so the user can verify the source before acting.

Continuous transparency

The Trust Center holds our current certificates, the full control list, subprocessors and change notices. Its content is updated continuously: controls are monitored, subprocessor changes are published, and new certificates appear as soon as they are issued.