Already in place
- ISO/IEC 27001:2022. Information security management system certified by QMS Certification — certificate QMS-03419, with scope, validity and verification below. The Information Security Policy is public (Portuguese).
- Data in Brazil. Hosted on AWS, São Paulo region, within the domestic scenario of CMN Resolution 4,893/2021. We provide the information and clauses your institution needs for its notification to the Central Bank. Segregation per client, encryption in transit and at rest, MFA and least privilege.
- Penetration test. Performed by an independent firm, with an executive summary available during vendor assessment.
- Audit trail per field. Document, rule, model and call traceable per operation. In a regulatory review, every opinion explains itself step by step.
Certification
ISO/IEC 27001:2022
GarantiaBR Ltda. Information Security Management System certified under ISO/IEC 27001:2022 by QMS Certification.
- Certificate
- QMS-03419
- Certification body
- QMS Certification
- Valid
- from 16/09/2026 to 15/09/2029
- Scope
- Development, operation, and support of a SaaS-based decision infrastructure platform for financial institutions.
Verify at the certification body →
The certification covers the management system, not a product or service.
How we handle personal data
- LGPD roles. In most flows GarantiaBR acts as a processor of personal data on behalf of the institution, which is the controller. When we acquire a document directly from a public source on our own account, we are the controller of that source data. Source data instead of credit bureaus, by default. DPA template available during assessment. Identity and contact of the data protection officer in the Privacy Policy.
- Right to review (art. 20). No platform output is a decision. Every assessed cell goes to your institution’s desk, which confirms, corrects or rejects. By rule, you define which findings are blocking and which are informational.
How we govern AI
- Validation before production. Every model is validated against reference sets before any promotion, and accuracy is monitored per document type.
- Continuity. Documented AI vendor and continuity policy.
- Your documents do not train models. It is a contractual clause with our AI providers.
The assessment package
Privacy policy, Terms of use and the Information Security Policy are public (Portuguese). The management system summary, the DPA template and a pre-filled third-party questionnaire go to your compliance team under a confidentiality agreement, starting from the form.