This English version is provided for convenience. In case of any discrepancy, the original Portuguese version prevails.
1. Introduction
Tradsul is committed to conducting its operations with the highest standards of information security, integrity and confidentiality. We recognize that protecting the data of our clients, partners and claims-adjusting processes is fundamental to the longevity of the business and the integrity of the insurance market. This Policy sets out our unwavering commitment to preserving the confidentiality, integrity and availability of information assets, in line with applicable legislation, such as Brazil's General Data Protection Law (LGPD), and corporate security best practices.
2. Purpose
This Information Security Policy (ISP) establishes the organizational guidelines and rules to protect information assets against unauthorized access, unwanted changes, leaks, service interruptions or any other threat that could compromise business operations.
3. Scope
The policy applies to all employees, directors, interns, service providers, third parties, consultants and partners who have access to the organization's information systems, networks, databases and physical or digital documents.
The organization's information security is based on four essential pillars:
- Confidentiality: ensuring that information is accessible only to duly authorized individuals, entities or processes.
- Integrity: safeguarding the accuracy and completeness of information and processing methods, preventing unauthorized or accidental changes.
- Authenticity: ensuring the identity of a user, system or source of information in transactions and communications.
- Availability: ensuring that authorized users have access to information and the corresponding assets whenever needed to perform their duties.
4. General Security Guidelines
4.1 Access Control and Identity Management
- Principle of Least Privilege: each user will have only the access strictly necessary to perform their duties.
- Access Credentials: accounts are personal and non-transferable. Sharing passwords is expressly prohibited.
- Authentication: strong passwords and multi-factor authentication (MFA) are required on all corporate systems and remote access.
- Workstation Lock: workstations must be locked whenever the user steps away.
4.2 Information Classification and Handling
Corporate information must be classified according to its level of criticality and sensitivity:
- Public: information whose access or external disclosure poses no operational, financial or reputational risk or harm to the company. Examples: institutional material, social media posts, press releases and public contact lists.
- Internal: information intended for routine use by internal staff. External disclosure is not authorized, but a leak would have low impact. Examples: internal rules and procedures, org chart, general board communications and system manuals.
- Confidential: information of strategic, financial or operational value. Unauthorized disclosure may result in contractual penalties, financial losses or reputational damage. Examples: claims-adjusting reports, expert reports, inspection photos, commercial proposals, quotes and contracts with insurers.
- Restricted: information of the highest legal and operational sensitivity, including Personal Data and Sensitive Personal Data (LGPD) or trade secrets of the company and its clients. Examples: bank details, policyholders' identity documents, system credentials and databases. Access is individualized, controlled by MFA, encrypted and auditable through logs.
4.3 Acceptable Use of IT Assets
Equipment provided (computers, smartphones, removable media) is intended exclusively for professional use.
Installing software not approved by the Technology and Information Security team is prohibited.
Storing confidential corporate data on personal cloud services or unmanaged devices is prohibited.
4.4 Security Incident Management
Any suspected or confirmed security incident (such as lost devices, leaked passwords, phishing e-mails or abnormal system behavior) must be reported immediately to the official Security/IT support channel.
The organization will maintain a documented Incident Response Plan, tested periodically, to contain, mitigate and remediate threats.
4.5 Business Continuity and Backups
- Backups: all critical systems must have automated daily backup routines.
- Restoration: periodic data restoration tests will be carried out (at least every six months) to validate backup integrity.
4.6 Physical and Environmental Security
A “Clean Desk and Clear Screen” policy is in place: papers containing confidential information must not be left exposed on desks at the end of the workday, and computer screens must be locked.
5. Roles and Responsibilities
- Senior Management: approve the ISP, provide the resources needed to implement it and promote a security culture within the company.
- Security / IT Committee: draft, periodically review and ensure the application of the technical and operational rules described in this policy.
- Area Managers: ensure their teams follow the ISP guidelines and identify operational risks specific to their routines.
- Employees and Third Parties: read, understand and sign the Commitment Agreement and strictly comply with the rules set out in this ISP.
6. Awareness and Training
The organization will provide mandatory Information Security and Privacy awareness training to all new employees during onboarding, as well as ongoing refresher campaigns (at least annually).
7. Penalties and Sanctions
Failure to comply with the guidelines and rules established in this Information Security Policy constitutes a disciplinary offense, subjecting the offender to the following sanctions, applied individually or cumulatively depending on the severity of the offense:
- Verbal or written warning.
- Temporary suspension.
- Dismissal for cause or immediate contract termination (for service providers/third parties).
- Civil and criminal liability as provided under current legislation.
8. Review and History
This policy is valid indefinitely and will be reviewed annually, or on an extraordinary basis whenever there are significant changes to the organization's infrastructure, legislation or strategic objectives.
