GarantiaBR
PortuguêsBook a demo

Security and compliance

Built to pass your vendor assessment.

Security is a condition of purchase, not a sales pitch. Here is what your compliance team will ask, answered before the meeting.

Already in place

  • ISO/IEC 27001:2022. Information security management system certified by QMS Certification — certificate QMS-03419, with scope, validity and verification below. The Information Security Policy is public (Portuguese).
  • Data in Brazil. Hosted on AWS, São Paulo region, within the domestic scenario of CMN Resolution 4,893/2021. We provide the information and clauses your institution needs for its notification to the Central Bank. Segregation per client, encryption in transit and at rest, MFA and least privilege.
  • Penetration test. Performed by an independent firm, with an executive summary available during vendor assessment.
  • Audit trail per field. Document, rule, model and call traceable per operation. In a regulatory review, every opinion explains itself step by step.
QMS Certification Certified Company seal, ISO/IEC 27001

Certification

ISO/IEC 27001:2022

GarantiaBR Ltda. Information Security Management System certified under ISO/IEC 27001:2022 by QMS Certification.

Certificate
QMS-03419
Certification body
QMS Certification
Valid
from 16/09/2026 to 15/09/2029
Scope
Development, operation, and support of a SaaS-based decision infrastructure platform for financial institutions.

Verify at the certification body →

The certification covers the management system, not a product or service.

How we handle personal data

  • LGPD roles. In most flows GarantiaBR acts as a processor of personal data on behalf of the institution, which is the controller. When we acquire a document directly from a public source on our own account, we are the controller of that source data. Source data instead of credit bureaus, by default. DPA template available during assessment. Identity and contact of the data protection officer in the Privacy Policy.
  • Right to review (art. 20). No platform output is a decision. Every assessed cell goes to your institution’s desk, which confirms, corrects or rejects. By rule, you define which findings are blocking and which are informational.

How we govern AI

  • Validation before production. Every model is validated against reference sets before any promotion, and accuracy is monitored per document type.
  • Continuity. Documented AI vendor and continuity policy.
  • Your documents do not train models. It is a contractual clause with our AI providers.

The assessment package

Privacy policy, Terms of use and the Information Security Policy are public (Portuguese). The management system summary, the DPA template and a pre-filled third-party questionnaire go to your compliance team under a confidentiality agreement, starting from the form.

Shall we talk about your operation?

Request the assessment package (PT)