Fidelizador · Confianza y seguridadTrust & security
Trust Center

Tu información, tratada como un activo crítico.Your data, handled as a critical asset.

Operamos para gobierno, banca, salud y telecomunicaciones: industrias donde un error de seguridad no es una opción. Contamos con certificaciones, cumplimos con las normativas legales sobre privacidad y confidencialidad de datos.We operate for government, banking, healthcare and telecommunications: industries where a security slip isn't an option. We hold certifications and comply with the legal regulations on data privacy and confidentiality.

ISO 27001
Ver certificado vigente (PDF)View current certificate (PDF)
Cifrado AES-256AES-256 encryption
En tránsito y en reposoIn transit and at rest
Ley 21.719
Protección de datos personales (Chile)Personal data protection (Chile)
99,9% SLA
Disponibilidad y entregabilidad garantizadaGuaranteed uptime and deliverability
Seguridad de la informaciónInformation security

Defensa en profundidad, no en titulares.Defense in depth, not in headlines.

Cada capa —infraestructura, aplicación, datos y personas— tiene controles propios, auditados y monitoreados 24/7.Every layer —infrastructure, application, data and people— has its own controls, audited and monitored 24/7.

Cifrado de extremo a extremoEnd-to-end encryption

  • TLS en tránsito; AES-256 en reposoTLS in transit; AES-256 at rest
  • Webhooks firmados con JWSJWS-signed webhooks
  • Trazabilidad completa de eventos y accesosFull traceability of events and access

Control de accesoAccess control

  • MFA obligatorio y SSO/SAMLEnforced MFA and SSO/SAML
  • Roles granulares (RBAC) por workspaceGranular roles (RBAC) per workspace
  • Principio de menor privilegioLeast-privilege by default

Monitoreo y respuestaMonitoring & response

  • SOC 24/7 con detección de anomalías24/7 SOC with anomaly detection
  • Plan de respuesta a incidentes probadoTested incident response plan
  • Pentesting externoExternal pentesting

Resiliencia de datosData resilience

  • Redundancia activa-activa entre regionesActive-active cross-region redundancy
  • Respaldos cifrados cada horaHourly encrypted backups
  • RPO < 1 h · RTO < 4 h

Trazabilidad y auditoríaTraceability & audit

  • Timeline completo por mensajeFull per-message timeline
  • Logs de actividadActivity logs
  • Exportable a tu SIEMExportable to your SIEM

Seguridad en las personasPeople security

  • Background checks al equipoTeam background checks
  • Capacitación de seguridad obligatoriaMandatory security training
  • Acuerdos de confidencialidad del personalStaff confidentiality agreements
  • Acceso a producción auditadoAudited production access
Cumplimiento normativoRegulatory compliance

Conocemos las reglas de cada mercado.We know the rules of each market.

Operamos en LATAM, con sus marcos legales propios. No es un anexo: es parte del diseño del producto.We operate across LATAM, each with its own legal framework. It's not an annex: it's part of the product design.

Ley 21.719
Chile · Datos personalesChile · Personal data

Nueva ley de protección de datos personales de Chile. Tratamiento basado en consentimiento, derechos ARCO, y la figura de la Agencia de Protección de Datos. Estamos alineados con sus exigencias para responsables y encargados de datos.Chile's new personal data protection law. Consent-based processing, data subject rights, and the new Data Protection Agency. We're aligned with its requirements for controllers and processors.

CumpleCompliant
Ley 19.628
Chile · Vida privadaChile · Privacy

Marco histórico de protección de la vida privada en Chile. Mantenemos cumplimiento durante el período de transición hacia la Ley 21.719.Chile's historical privacy framework. We maintain compliance through the transition period toward Law 21,719.

CumpleCompliant
Ley 21.663
Chile · CiberseguridadChile · Cybersecurity

Ley Marco de Ciberseguridad de Chile. Establece deberes de gestión de riesgos, reporte de incidentes de ciberseguridad y la Agencia Nacional de Ciberseguridad. Nuestras prácticas de seguridad y nuestro protocolo de notificación de incidentes están alineados con sus exigencias.Chile's Cybersecurity Framework Law. It sets duties for risk management, cybersecurity incident reporting, and creates the National Cybersecurity Agency. Our security practices and incident notification protocol are aligned with its requirements.

CumpleCompliant
GDPR
UE · Por solicitudEU · On request

Para clientes con contactos en la Unión Europea, ofrecemos acuerdos de tratamiento de datos (DPA) y mecanismos de transferencia internacional conformes al RGPD.For customers with EU contacts, we offer Data Processing Agreements (DPA) and GDPR-compliant international transfer mechanisms.

CumpleCompliant
CAN-SPAM
Anti-spam · Buenas prácticasAnti-spam · Best practices

Doble opt-in, gestión de bajas en un clic, autenticación SPF/DKIM/DMARC y monitoreo de reputación. La entregabilidad empieza por enviar bien.Double opt-in, one-click unsubscribe, SPF/DKIM/DMARC authentication and reputation monitoring. Deliverability starts with sending right.

CumpleCompliant
Infraestructura de datacenter para comunicaciones críticas

Infraestructura regional para comunicaciones críticas.Regional infrastructure for critical communications.

Infraestructura primaria en ChilePrimary infrastructure in Chile

Infraestructura de datacenters dedicada y preparada para operar comunicaciones de alto volumen para clientes en Chile, Perú, México y otros mercados de la región.Dedicated datacenter infrastructure, ready to operate high-volume communications for customers in Chile, Peru, Mexico and other markets in the region.

Respaldo regional cifradoEncrypted regional backup

Respaldos cifrados en infraestructura de cloud, diseñados para contribuir a la recuperación y continuidad operativa ante incidentes, sin exponer la información de los clientes.Encrypted backups on cloud infrastructure, designed to support recovery and operational continuity during incidents, without exposing customer information.

Aislamiento por clientePer-customer isolation

Cada cliente opera con sus datos lógicamente separados y cifrados. Entornos estrictamente confinados y auditados.Each customer runs with their data logically separated and encrypted. Strictly confined and audited environments.

Compromisos que medimos.Commitments we measure.

99,9%
Disponibilidad garantizada por SLAUptime guaranteed by SLA
< 3 s
Latencia envío transaccionalTransactional send latency
< 1 h
Tiempo 1ra respuesta soporteSupport first-response time
24/7
Monitoreo de infraestructuraInfrastructure monitoring
DocumentaciónDocumentation

Todo lo que tu equipo legal necesita.Everything your legal team needs.

Preguntas de seguridad frecuentes.Common security questions.

¿Dónde se almacenan físicamente los datos?Where is data physically stored?+

En datacenters homologados Tier III en Chile, con respaldos cifrados de continuidad. Para un cliente con residencia en Chile, la operación ordinaria del servicio no implica que sus datos salgan del país. Los flujos que excepcionalmente se tratan fuera de Chile están identificados, con su mecanismo de garantía, en la lista de subencargados; el detalle legal está en la Política de Privacidad y en el Anexo A de los Términos de Servicio.In Tier III certified datacenters in Chile, with encrypted continuity backups. For a customer with residency in Chile, ordinary operation of the service does not mean their data leaves the country. The flows that exceptionally are processed outside Chile are identified, with their safeguard mechanism, in the sub-processor list; the legal detail is in the Privacy Policy and Annex A of the Terms of Service.

¿Firman un DPA y NDA?Do you sign a DPA and NDA?+

Sí. Tenemos plantillas de DPA listas y firmamos NDAs sin problema. Para Enterprise, también revisamos tus propios documentos.Yes. We have ready DPA templates and sign NDAs without issue. For Enterprise, we also review your own documents.

¿Cómo manejan un incidente de seguridad?How do you handle a security incident?+

Tenemos un plan de respuesta a incidentes probado. Ante una vulneración con riesgo razonable para los derechos de los titulares notificamos al cliente sin dilación, reportamos a la Agencia de Protección de Datos Personales conforme al artículo 14 sexies de la Ley 19.628 y, como prestador de servicios digitales, al CSIRT Nacional conforme a la Ley 21.663: alerta temprana en 3 horas, evaluación inicial en 72 horas e informe final tras la contención. Cada incidente genera un post-mortem compartible.We have a tested incident response plan. In the event of a breach posing a reasonable risk to data subjects' rights we notify the customer without delay, report to the Personal Data Protection Agency under article 14 sexies of Law 19,628 and, as a digital service provider, to the National CSIRT under Law 21,663: early warning within 3 hours, initial assessment within 72 hours and a final report after containment. Every incident produces a shareable post-mortem.

¿La integración con IA es segura?Is the AI integration secure?+

El servidor MCP usa permisos granulares: por defecto todo está apagado. Tú defines qué herramientas y segmentos expone, con aprobación humana configurable y auditoría completa.The MCP server uses granular permissions: everything is off by default. You define which tools and segments it exposes, with configurable human approval and full audit.

¿Puedo revisar su política de seguridad de la información?Can I review your information security policy?+

Sí. La Política General de Seguridad de la Información (documento P01, versión 3.1, del 24 de julio de 2025) es de clasificación pública y está publicada íntegra en fidelizador.com/politica-seguridad, junto al certificado ISO/IEC 27001:2022 vigente emitido por AENOR.Yes. The General Information Security Policy (document P01, version 3.1, dated July 24, 2025) is classified as public and is published in full at fidelizador.com/politica-seguridad, alongside the current ISO/IEC 27001:2022 certificate issued by AENOR. Ver la política de seguridadView the security policy

¿Tu equipo de seguridad tiene preguntas?Does your security team have questions?

Agenda una sesión con nuestro equipo de seguridad de la información. Respondemos cuestionarios de proveedores y revisamos tu due diligence.Book a session with our information security team. We answer vendor questionnaires and walk through your due diligence.

Hablar con seguridadTalk to security

[email protected][email protected]