Cybersecurity and software development for companies
Tox tests the security of systems already in production and builds new systems with security designed in from the start. We work with credit unions, manufacturers, agribusiness cooperatives, retailers and technology companies, on fixed-scope projects and monthly contracts.
Request a proposalPricing on request.
Companies under ongoing contract
Cybersecurity
Penetration testing, hardening, data protection, AI security and monthly follow-up for systems in production.
- Penetration testing
- Authorized testing of web applications, APIs and apps, with a report on every confirmed finding and a retest after the fix.
- Hardening and OWASP Top 10
- Fixes for the OWASP Top 10:2025 categories and a review of application, server, database and dependency configuration.
- Authentication and access control
- MFA, OAuth2 and SSO, role-based permissions and row-level isolation in the database.
- Data protection compliance
- Technical compliance with Brazil's LGPD: data inventory, retention, data subject requests and incident reporting.
- AI security
- Testing chatbots and AI agents for prompt injection, data leakage and unauthorized actions.
- DDoS protection
- Finding the routes that fail first under abnormal traffic, rate limiting, edge protection and a response plan.
- Data encryption
- Protection of sensitive data in transit, at rest and in backups, with key and secret management.
- Secure code review
- Reading the source code for authorization flaws, injection, business logic errors and exposed secrets.
- Continuous security
- Monthly contract: review of each release, dependency monitoring, periodic tests and incident response.
Software development
Web systems, SaaS, portals, mobile apps and integrations, delivered to production and maintained under contract.
- Custom software
- Web systems built around the company's own process, with access control, integrations and support after delivery.
- SaaS development
- Subscription platforms with multi-tenant architecture, recurring billing and per-customer data isolation from day one.
- Websites and online stores
- Corporate websites, landing pages and online stores with technical SEO and secure checkout.
- Automation and AI
- AI agents and WhatsApp support integrated with company systems, with access limits enforced outside the model.
- Integrations and APIs
- Connections to banks, Brazilian instant payments (Pix), electronic invoicing, WhatsApp and ERPs, with retries when the other side fails.
- iOS and Android apps
- Apps for field teams and customers, published on the App Store and Google Play and linked to the same web system.
- Customer and supplier portals
- Logged-in areas where customers, members or suppliers find documents, open requests and track orders.
- Legacy system modernization
- Replacing old systems and spreadsheets in stages, without stopping operations and without losing history.
- Maintenance and evolution
- Monthly contract to keep the system running: monitoring, fixes, updates, backups and continuous improvements.
Industries
Each industry has its own fraud patterns, regulations and systems. These are the ones where Tox holds ongoing contracts.
- Financial services and credit unions
- Credit unions, fintechs and payment companies subject to the Central Bank of Brazil's cybersecurity rules, which require an independent penetration test every year.
- Manufacturing
- Supplier portals, order systems and ERP integrations in companies where an incident stops production.
- Agribusiness and cooperatives
- Agribusiness cooperatives with member portals, crop trading systems and data on thousands of members.
- Retail and e-commerce
- Online stores, checkout and loyalty programs, constant targets of automated fraud.
- Technology and SaaS
- Software companies that need to demonstrate security to sell to enterprise customers.
How we work
Scoping call
We learn about the system, the process and what concerns the company. No access is requested at this stage.
Proposal and contract
Fixed scope, timeline and price. A non-disclosure agreement and, for security work, a signed testing authorization.
Execution in stages
Testing or development within the agreed limits, with partial deliveries and a technical contact from your team.
Delivery and follow-up
Report and retest, or the system in production with training. If you wish, we continue under a monthly contract.
About Tox
Tox started in 2020 with security. Its first project was the security audit and implementation of uTox, a C client for the Tox end-to-end encrypted messaging protocol, which is where the company name comes from.
Today Tox tests the security of third-party systems and builds systems for companies. The two activities feed each other: flaws we find in tests become rules in our development, and knowing code from the inside helps us know where to look when testing.
All work is covered by non-disclosure agreements. That is why this site shows the companies we work with but does not describe what was done for each one.
Detailed service pages, articles and legal documents are currently available in Portuguese. tox.dev.br
Request a proposal
Tell us about the system and what concerns your company. You do not need a finished scope: we define it together in the first conversation.
What happens next
- We reply using the contact you provide.
- We schedule a call to understand the system. No access is requested at this stage.
- You receive a proposal with defined scope and timeline, under a non-disclosure agreement.
Prefer email? Write to contato@tox.dev.br











