Commitment to information protection and data privacy.
ISO 27001 is an international standard that guides companies in managing information security. It ensures that sensitive data is protected against unauthorized access, leaks, and losses. For companies, it represents process maturity and risk reduction, conveying trust and credibility to clients.
Because it demonstrates that the company protects its data seriously, following international information security standards. This reduces risks, ensures compliance with laws, conveys trust to clients, and strengthens the brand’s credibility in the market.
ISO 27001 and the LGPD complement each other in data protection. ISO 27001 provides best practices for ensuring information security, while the LGPD regulates the use of personal data in Brazil. By following ISO, the company strengthens its security structure and meets several LGPD requirements, demonstrating its commitment to privacy and legal compliance.
Discover the path we took to reach this important milestone in our history.
In 2021, we identified the need to obtain ISO certification but chose to postpone the process, as we were still structuring company operations and expanding the team to establish well-defined areas.
We resumed the certification idea during the planning of our in-person meeting, when the ISO topic had been gaining traction internally. In this year, with more structured processes and a larger team working in the areas, the initiative returned more mature and aligned with our organizational moment.
We hired an audit aiming to obtain certification and decided that we would go through the entire process still in 2024. Throughout the year, we matured the certification idea and, in the second semester, carried out a pre-audit as preparation.
We successfully passed phases 1 and 2 of the audit, the first conducted online and the second in person. In both, no major nonconformities were identified. This result reflects our continuous investment in technology, training, skills development, studies, and alignment. All with a clear goal: consolidating certification as part of our security culture.
Certificate issuance in the second half of 2025.
Important moments from our certification journey.
Team during the initial audit with consultants
IT team implementing security controls
Celebration of achieving ISO 27001 certification
Our commitment to data protection goes beyond ISO 27001 certification.
We identify all personal data flows in our systems and processes.
We ensure that all personal data processing has an appropriate legal basis.
We implement processes to comply with data subjects' rights under the LGPD.
We adopt technical and organizational measures to protect personal data.