01Purpose and scope
This Security Statement describes the technical and organisational controls implemented by AENVO Natural Interaction, Lda. to protect the confidentiality, integrity and availability of its systems, data and digital services.
The scope of this Statement covers AENVO's institutional website, applications, APIs, artificial intelligence models and conversational service systems, namely the agents Nuno, Sofia and Miguel, as well as the supporting infrastructure on which these systems operate.
AENVO provides services in Portugal and Brazil and operates in compliance with the legislation applicable in each jurisdiction: Regulation (EU) 2016/679 (GDPR) and Portuguese Law no. 58/2019 for operations in the European Union, and Law no. 13.709/2018 (LGPD) for operations in Brazil. System security is further guided by Regulation (EU) 2024/1689 (AI Act), Portuguese Decree-Law no. 125/2025 (NIS2, adopted voluntarily), Directive (EU) 2019/882 (EAA) and the ISO/IEC 27001:2022 and ISO/IEC 27701:2019 standards.
02Security principles
AENVO adopts a defence-in-depth approach based on the following fundamental principles, which guide every security and development decision: privacy by design, pursuant to Article 25 of the GDPR; security by design; data minimisation; the principle of least privilege; and strict separation between development, test and production environments.
These principles are aligned with the requirements of Articles 25 and 32 of the GDPR, with the risk management system provided for in Article 9 of the AI Act and with the controls of ISO/IEC 27001:2022.
03Access and identity management
AENVO implements Role-Based Access Control (RBAC), ensuring that each employee and system accesses only the information and features strictly necessary to perform their responsibilities. Multi-factor authentication (MFA) is mandatory for all accounts with privileged access to critical systems and sensitive data.
Access tokens and keys are managed rigorously, with periodic rotation and secure storage. Access permissions are reviewed periodically and removed immediately when an employee leaves or changes responsibilities. The principle of segregation of critical duties is maintained, preventing any single person from having full control over sensitive processes without supervision.
These controls fall within the obligations of Article 32 of the GDPR and the minimum cybersecurity measures of Article 21(i) of the NIS2 Directive, adopted voluntarily by AENVO.
04Encryption
All data processed by AENVO is protected by strong encryption. In transit, TLS 1.2 or higher is used for all communications between AENVO's systems and end users. At rest, data is encrypted with the AES-256 standard, including voice biometric data, which is classified as special category data under Article 9 of the GDPR and subject to reinforced encryption and additional access controls.
Cryptographic key management includes regular rotation and secure storage in digital vaults, ensuring that keys are never exposed in production systems. These controls fall within the obligations of Article 32 of the GDPR and the measures of Article 21(h) of the NIS2 Directive.
05Network security
AENVO's infrastructure uses network segmentation and strict access control lists to isolate the different components of the system and limit the attack surface. Next-generation firewalls and Web Application Firewalls (WAF) protect applications against external attacks, together with protection mechanisms against distributed denial-of-service (DDoS) attacks.
For enterprise customers, integration with virtual private networks (VPC peering) and IP address restriction rules are supported. The entire network infrastructure is continuously monitored for anomalies and suspicious behaviour. These controls fall within the requirements of ISO/IEC 27001:2022 and the measures of Article 21 of the NIS2 Directive.
06Logging, auditing and monitoring
AENVO keeps detailed security and application logs for auditing, traceability and troubleshooting purposes. Security logs are retained for a minimum period of six months, in line with ISO/IEC 27001:2022 best practices and the traceability requirements established by Article 12 of the AI Act.
Logs of the operations of the artificial intelligence agents Nuno, Sofia and Miguel are generated automatically to ensure full traceability of interactions, in compliance with Article 12 of the AI Act. These logs make it possible to reconstruct how the system behaved in the event of an incident and to demonstrate compliance to the competent authorities.
Intrusion Detection Systems (IDS) and Security Information and Event Management (SIEM) systems are used for real-time analysis. Automatic alerts and documented response procedures are triggered whenever anomalies or suspicious behaviour are detected.
07Vulnerability management and testing
AENVO performs vulnerability scans on its systems and applications at regular intervals, applying security fixes and updates continuously and as a priority. A formal patch management process ensures that critical vulnerabilities are fixed within defined deadlines.
Penetration tests are carried out at regular intervals by independent, specialised external companies. Results are documented and identified vulnerabilities are handled according to their criticality. A responsible vulnerability disclosure programme allows external security researchers to report vulnerabilities via security@aenvo.ai.
These controls fall within the measures of Article 21(e) of the NIS2 Directive.
08Secure development lifecycle (SSDLC)
Security is an integral part of AENVO's development lifecycle, applied from the design phase onwards. Security architecture reviews, threat modelling, security quality control and peer code review are carried out before any deployment to the production environment.
All software dependencies are monitored automatically for known vulnerabilities, and a strict version management policy with rollback mechanisms is maintained for rapid reversal in the event of problems.
The technical documentation of the artificial intelligence systems required by Article 11 of the AI Act is being prepared, including a description of the agents' architecture, the data used in development, the capabilities and limitations of each system and the human oversight procedures provided for in Article 14 of the AI Act.
09AI-specific security
Given the nature of AENVO's conversational artificial intelligence services, additional security measures specific to AI systems are implemented, in compliance with Regulation (EU) 2024/1689 (AI Act).
- Data segregation: strict logical isolation between the data of different customers and the models' training datasets.
- Training control: users have clear opt-out options regarding the use of their data to refine the models.
- Model protection: mitigation mechanisms against prompt injection attacks and content filters to prevent inappropriate or harmful responses.
- Voice anti-spoofing: liveness detection mechanisms to prevent fraud in the voice biometric authentication process.
- Data sanitisation: the ability to automatically hide or mask sensitive personal data before it is processed by language models.
- Continuous monitoring: permanent tracking of model quality and behaviour, detecting drift and performance degradation.
- Technical marking of generated content: the outputs of AENVO's artificial intelligence agents carry machine-readable technical marking, pursuant to Article 50(2) of the AI Act, allowing the content to be identified as artificially generated. For systems placed on the market before 2 August 2026, this technical marking will be implemented by 2 December 2026, in accordance with the transition period provided for in the legislation.
These measures fall within the following obligations of the AI Act: Article 4 requires adequate AI literacy for all employees working with artificial intelligence systems; Article 5 prohibits inferring users' emotional states for categorisation or decision-making purposes, a practice AENVO declares it does not carry out in its systems; Article 12 requires automatic logging of the agents' operations; Article 14 ensures effective human oversight mechanisms allowing an operator to intervene whenever necessary; and Article 50 requires agents to be identified as AI systems and generated content to be technically marked.
10Incident management
AENVO maintains a formal incident response process with severity classification and defined target times for containment, eradication and recovery. The process is documented and tested periodically to ensure its effectiveness.
In the event of a personal data breach, the Data Protection Officer is notified immediately and assesses whether the competent authorities must be notified within the legal deadlines: the Portuguese Data Protection Authority (CNPD) within 72 hours of becoming aware of the incident, pursuant to Article 33 of the GDPR; and the Brazilian National Data Protection Authority (ANPD) within 2 working days, pursuant to Article 48 of the LGPD, for operations involving data of Brazilian data subjects. Where the breach represents a high risk to the rights and freedoms of data subjects, they are also notified without undue delay, pursuant to Article 34 of the GDPR and Article 48 of the LGPD.
As a cybersecurity best practice, AENVO voluntarily adopts the reference deadlines of the NIS2 Directive: initial alert to the Portuguese National Cybersecurity Centre (CNCS) within 24 hours, interim report within 72 hours and final report within 30 days of detection.
For incidents involving artificial intelligence systems that may constitute a serious risk, AENVO is preparing to meet the notification obligations provided for in Article 73 of the AI Act. After each incident, post-incident analyses are carried out to identify the root cause, implement corrective actions and prevent recurrence.
11Business continuity and disaster recovery (BCP/DR)
AENVO ensures the resilience of its services through encrypted backups and periodic, documented restoration tests. The Recovery Time Objective (RTO), Recovery Point Objective (RPO) and Maximum Tolerable Downtime (MTD) are formally defined for critical systems.
Failure scenario exercises are carried out to validate the effectiveness of recovery plans, and geographic redundancy is used in the cloud infrastructure to mitigate the impact of localised outages. The Business Continuity Plan (BCP) and the Disaster Recovery Plan (DRP) are documented, approved by senior management and reviewed periodically.
These controls fall within the measures of Article 21(c) of the NIS2 Directive and the requirements of ISO/IEC 27001:2022.
12Processors and physical infrastructure
AENVO partners exclusively with cloud infrastructure providers that hold internationally recognised security certifications. The cloud infrastructure is supported by Google Cloud Platform and Amazon Web Services, both certified ISO/IEC 27001 and SOC 2. It should be noted that these certifications refer to the providers' physical infrastructure and internal processes and do not replace AENVO's internal security responsibilities for the secure configuration of services within that infrastructure.
AENVO's internal security measures are aligned with ISO/IEC 27001:2022 and ISO/IEC 27701:2019, adopted voluntarily. All processors are bound by Data Processing Agreements (DPA) pursuant to Article 28 of the GDPR and, for operations involving data of Brazilian data subjects, in compliance with Article 40 of the LGPD. A periodic risk assessment is carried out on all critical suppliers, in line with the measures of Article 21(d) of the NIS2 Directive.
13Training and awareness
All AENVO employees complete mandatory annual training in information security and data protection, ensuring that the security culture runs across the entire organisation. Phishing simulations are conducted and internal acceptable use policies for the systems are maintained.
Training also covers the obligations arising from the AI Act, in particular the AI literacy requirements of Article 4, which requires all employees working with artificial intelligence systems to have knowledge and skills appropriate to the context of their roles. AI training content covers how the systems work, the associated risks, the applicable legal obligations, the practices prohibited by Article 5 of the AI Act and the internal procedures for reporting anomalies and incidents.
These requirements also fall within the measures of Article 21(g) of the NIS2 Directive, adopted voluntarily by AENVO.
14Digital accessibility
AENVO is committed to the accessibility of its digital services, in compliance with Directive (EU) 2019/882 and Portuguese Decree-Law no. 82/2022, in force since 28 June 2025. The security measures implemented have been designed not to create accessibility barriers, ensuring that users with visual, hearing, motor or cognitive disabilities can access and use the services with a level of security equivalent to that of other users. The Accessibility Statement is available online. Users who need assistance can contact AENVO at legal@aenvo.ai.
15Security contact
- Reporting vulnerabilities, incidents or security issues: security@aenvo.ai
- Privacy and personal data protection: privacy@aenvo.ai
- Legal and contractual matters: legal@aenvo.ai
- Digital accessibility: legal@aenvo.ai