This is an English translation; the Spanish version prevails.
Security policy
How we protect data and how to report a vulnerability to us.
1. Measures we apply
Encryption in transit: all traffic uses HTTPS with automatically renewed certificates.
Third-party credentials (WhatsApp tokens, API keys, integrations) encrypted at rest with AES-256-GCM.
Passwords stored with a strong hashing function (scrypt), never in plain text.
Two-step verification for Dona staff, lockout after repeated failed sign-ins, and sign-out of every session when a password is reset.
Audit log of sign-ins and sensitive actions, kept for one year.
Access to customer data limited to the staff who need it to provide the service.
Isolation of customer websites from panel and CRM sessions.
Daily encrypted backups, also stored off the main server, with periodic restore tests.
Firewalled servers (only required ports), automatic security updates and monitoring with alerts.
2. Incidents
If a security incident affects personal data we investigate and contain it immediately and notify affected Customers without undue delay (where possible within 48 hours), and the authorities where required.
3. Reporting a vulnerability
If you find a vulnerability, write to seguridad@joindona.com with the details to reproduce it. Please do not access other people's data beyond the minimum needed to demonstrate it, do not affect the availability of the Service, and give us reasonable time to fix it before making it public. We will not take action against anyone reporting in good faith under these guidelines.
Last updated: 2026-09-28