What we do · Security and compliance

Security and Compliance

Corporate security starts with design and continues through operation. We assess risks, incorporate controls into the architecture, support LGPD and GDPR compliance and prepare companies for certification. Our team implements the necessary fixes, organizes evidence and rehearses incident response with business owners.

ShapeConsultancy, then planning, implementation and retainer
First stepThreat model assessment, 2 to 3 weeks
ReferencesLGPD, ANPD guidance, GDPR, ISO/IEC 27001 and 27701, ISO/IEC 42001, SOC 2 Type II, TISAX, PCI DSS, NIS2, DORA, HIPAA, CCPA, AI Act

Interactive Assessment

Assess Your Protection Priorities

Explore the threats and privacy concerns relevant to your activities. The assessment organizes the issues requiring attention and practical next steps, with answers processed locally in your browser.

Activities connect information, people and services. The assessment follows these relationships to identify what needs protection.PeopleServicesInformationDecisionsYour ActivityMap the Relationships

The picture: who tries

A threat model answers practical questions: who wants what the client holds, what can they do to get it, and what does it cost to stop them? These are the actors we encounter most often.

Criminal groups

Extortion by ransomware, fraud through compromised corporate e-mail, mass credential theft. They operate like companies and pick targets by the ratio of effort to return.

Corporate espionage

Competitors, or third parties hired by them, after secrets, proposals, litigation and unannounced plans.

People close by

Former employees with active accounts and contractors with excessive permissions. Regular access reviews reduce exposure and make responsibilities verifiable.

What we do

  • Threat modelWho has an interest, what they can access today and what it costs to change that. Written, reviewed with the client and updated as relevant actors and their capabilities change. It grounds every decision that follows.

  • Security and governance from the design stageData minimization, separation of duties, encryption, access control and event logging defined in the architecture and verified on delivery.

  • LGPD and GDPR complianceInventory of personal data, flows, purposes and legal bases; impact assessment; retention with automatic deletion; a defined process for data-subject requests; processor contracts and international transfers. Every gap comes with a quote to fix it.

  • Certification and regulatory readinessWe guide companies and professionals through the independent audit: ISO/IEC 27001 and 27701, SOC 2 Type II, TISAX, PCI DSS; readiness for HIPAA, NIS2, DORA and CCPA. Gap analysis, a plan prioritized by risk, controls implemented, an evidence pack, and support through the maintenance cycles.

  • Security assessment, hardening and defenseReview of configuration, identity and access, code and infrastructure, with fixes applied; active defense with agents inside the client's perimeter; adversary emulation and intrusive testing with a target, a scope, a window and written authorization.

  • Rehearsed incident responseA written response plan for the threat scenarios, rehearsed with the people responsible, including notification of authorities and data subjects within the legal deadline.

What you receive

From the consultancy, the written threat model, the inventory of what was found and a plan with priorities and an effort estimate for each item. From planning, the protection architecture proportionate to the risk, with decisions recorded. From implementation, the controls built and verified. From the retainer, periodic review of the model and the controls, handling of client questionnaires and data-subject requests, and a monthly report of what changed. Every delivery comes with evidence in a form an auditor, a regulator or a client can read without calling us.

Threat model assessment

2 to 3 weeks · fixed price · companies and technology teams

Interviews with operators and decision-makers, an inventory of systems, data, devices and accounts, and a review of contracts and configurations. The result is the written model, with the relevant actors, what each can access today and what it costs to change that, and the protection plan with estimated effort. Nothing is altered in this phase without written authorization.

Request a Conversation

LGPD and GDPR readiness

3 to 4 weeks · fixed price

Inventory, legal bases, gaps and a quote for the remediation work.

Request a Conversation

Certification readiness

Fixed scope · ISO/IEC 27001 and 27701, SOC 2 Type II, TISAX, PCI DSS

Gaps against the chosen standard, a plan prioritized by risk, controls implemented and an evidence pack for the independent audit.

Request a Conversation

Frequently asked

Is a threat model useful for a small company?

It is, and it is usually the most affordable security investment a company will make, because it defines which controls a limited budget should go to.

Do you also do the remediation?

Yes. The client may carry out the plan with any team they choose, but the standard proposal includes implementing and maintaining what was decided.

Do you accompany us through to certification?

Yes, the whole way: gaps against the chosen standard, a plan prioritized by risk, controls implemented and the evidence pack for the third-party audit that leads to the certificate. After it, we stay on for the maintenance cycles the standard requires.