Compliance
We apply established practices drawn from standards, certifications and regulations around the world: data protection in Brazil and Europe, information security and privacy management, business continuity, cloud, payments and regulated sectors. These practices guide how we design, build and operate. They also inform our work with companies and professional teams pursuing compliance or certification.
The practices we follow. The evidence your organization needs.
We adopt the controls of the standards as our own method and apply them on every project. When a client needs to prove compliance or pursue a certification, we follow the same process we use internally: gap analysis against the chosen standard, a plan prioritized by risk, controls implemented and the evidence pack the third-party audit will ask for.
Security and governance by design
The systems we build and the infrastructure we operate incorporate data minimization, encryption in transit and at rest, access control, separation of duties and event logging defined in the architecture and verified on delivery. Permissions, retention and support procedures are documented to support accountable, auditable operations.
In practice
- Personal data handled under the LGPD: legal basis identified, purpose stated, retention defined, data-subject rights served through contact form within a documented response deadline.
- Our own and our clients' infrastructure operated under a documented baseline: controlled administrative access, key-only SSH, disk encryption, default-deny firewall, scheduled updates and tested backup.
- Credentials and sensitive information are handled through appropriate channels and tools, with access controls and documented procedures.
- An e-mail, a document or a page received from outside never triggers an action on its own; a person decides, and the system records the decision.
- Assessments of environments we built or supplied ourselves are described as quality control; when the client needs an independent assessment, we identify an independent assessor and prepare the environment.
- Intrusive testing requires a defined target, scope, time window and written authorization valid only for that test.
- Client identities and details of work performed remain confidential, including on this site, unless the client expressly authorizes otherwise.
Standards and regulations that guide the work
Data protection: LGPD, GDPR, CCPA and CPRA. Security and privacy management: ISO/IEC 27001, 27701, 27017 and 27018, ISO/IEC 42001 for artificial intelligence systems, ISO 22301 for continuity, SOC 2 Type II, TISAX, PCI DSS. Technical references: NIST CSF 2.0, CIS Controls, OWASP ASVS, MITRE ATT&CK. Regulated sectors: NIS2 and DORA in Europe, the EU AI Act, HIPAA, FINRA and SEC rules. The list grows as the client's sector requires.
How we support compliance and certification
We start from the standard or regulation the client has to meet and from the scope that makes sense to certify. We identify gaps, prioritize fixes by risk, implement the missing controls, bring in engineering where needed and assemble the evidence pack. By the independent audit, the client has a working system and the documentation to support it. We stay involved through the maintenance cycles the standard requires.