Skip to Content
Terms of UseInformation Security Policy

Information Security Policy

Introduction

This Information Security Policy (“Information Security Policy”) establishes the information security requirements for the SaaS innovation management platform. The Policy applies to all users of the Platform, including employees, customers, partners and suppliers.

Objective

The objective of this Policy is to protect the confidentiality, integrity and availability of information stored and processed on the Platform. The Policy also aims to ensure that the Platform is used in a safe and responsible manner.

Scope

This Policy applies to all Platform systems, networks, applications and data. The Policy also applies to all users of the Platform, including employees, customers, partners and suppliers.

Settings

  • Confidentiality: The property that information is only accessible to authorized people or systems.
  • Integrity: The property that the information is accurate and complete and has not been altered or corrupted without authorization.
  • Availability: The property that information is accessible and usable when necessary by authorized people or systems.
  • Data: Any information that can be stored, processed or transmitted through a computer system.
  • Platform: SaaS for innovation and project management.
  • Information Security: The protection of information against unauthorized access, use, disclosure, alteration or destruction.
  • User: Any person or system that accesses or uses the Platform

Access Control

  • Access to the Platform is controlled through authentication and authorization.
  • Only authorized users have access to data stored on the Platform.
  • Access to data is granted based on the principle of least privilege.
  • Passwords must be strong and confidential.
  • Passwords must be changed regularly.

Data Protection

  • Data is protected against unauthorized access, use, disclosure, alteration or destruction.
  • Data is encrypted when in transit.
  • Data is stored in a secure location.
  • Access to data is recorded and audited.

Network Security

  • The Platform network is protected against unauthorized access.
  • The Platform’s network is monitored to detect and prevent malicious activities.
  • Network security software is regularly updated.

Application Security

  • Applications are developed and tested securely.
  • Platform applications are regularly updated to fix security vulnerabilities.
  • User input data is validated to prevent code injection attacks.

Security Incident Management

When an incident occurs on the platform, it is crucial that the information security service provider has a well-defined support and escalation model to ensure an effective response and rapid resolution of the incident:

Support Levels:

  • Level 1 – Customer Success Team:

    • This is the first point of contact for customers reporting incidents through the portal.
    • Level 1 support representatives are responsible for receiving and recording incidents reported by customers.
    • They perform initial triage of incidents and attempt to resolve simple issues or escalate to higher levels of support if necessary.
  • Level 2 – Technical Team:

    • This level of support is made up of technical specialists with more advanced knowledge of the platform and systems involved.
    • They are responsible for resolving more complex issues that could not be resolved by Level 1 support.
    • Tier 2 support may involve further investigation, log analysis, and direct interaction with customers to resolve technical issues.
  • Level 3 – CTO:

    • This level of support involves the CTO dealing with advanced technical issues or infrastructure issues.
    • He is responsible for performing detailed analysis of complex problems, identifying and fixing flaws in source code, performing advanced configuration adjustments, and providing customized solutions to specific customer problems.

Scaling:

  • Escalation is the process of escalating an incident to higher levels of support or to individuals with additional skills and authority to resolve complex or critical issues.
  • Tier 1 support is responsible for determining whether an incident needs to be escalated to higher levels of support based on severity, business impact, and technical complexity.
  • Critical or high priority incidents are immediately escalated to higher levels of support.
  • Escalation is documented and tracked to ensure incidents are handled in a timely and effective manner.
  • Security incidents are investigated and remediated as quickly as possible.

Information Security and Remote Work

  • Information Security Obligations: The Contractor undertakes to fully follow the information security policies and procedures established by the contractor, ensuring the protection of data and digital assets. This includes implementing appropriate cybersecurity practices in software development, source code confidentiality, and compliance with data protection guidelines. Failure to comply with these obligations may result in immediate termination of the contract.
  • Use of Personal Devices (BYOD): The Contractor will be responsible for using its own devices to provide the services (BYOD), and must ensure that such devices meet all security requirements of the Contractor. This includes implementing and maintaining personal firewall, antivirus, EDR (Endpoint Detection and Response) and data loss prevention (DLP) systems. The Contractor undertakes to ensure that these security measures are always up to date and in proper working order.
  • The use of public or unsecured Wi-Fi networks to access systems, code repositories or any sensitive information of the Contractor is strictly prohibited. Any violation of this rule will be considered serious misconduct and may result in termination of the contract.
  • **Protection of Source Code and Confidential Information: **Any and all confidential information, including source code, customer data, commercial secrets and other sensitive information of the Contractor, must be treated with the highest degree of confidentiality by the Contractor. The Contractor must implement appropriate measures to ensure that this information is not inappropriately accessed, shared or disclosed. If any security incident occurs, the Contractor must immediately notify the Contractor.
  • Activity and Access Monitoring: The Contractor reserves the right to monitor activities in systems and tools related to software development and services provided, in order to ensure compliance with security policies. Contractor agrees to allow monitoring of its activities, including the use of version control tools and code repositories, and to provide records when requested by Contractor.
  • Responsibility for the Security of BYOD Devices: The Contractor is fully responsible for the physical and digital security of personal devices used for software development and provision of services. This includes protecting against theft, loss and damage, as well as keeping software up to date. If the devices are compromised, the Contractor must take immediate measures to mitigate the risks and notify the Contractor of any security incident
  • **Security and Compliance Audits: **The Contractor may carry out periodic audits to verify the compliance of the Contractor’s BYOD devices with the established security requirements. The Contractor must fully collaborate with these audits, providing the necessary access and information to ensure compliance with the security policies of the Contractor.
  • Security Training and Updates: The Contractor must participate in mandatory cybersecurity training, as requested by the Contractor, and remain up to date with best security practices in software development. Contractor shall also ensure that all BYOD devices are updated with the latest security fixes and software patches as required.
  • Software Maintenance and Technical Support: The Contractor is responsible for ensuring that all devices and software used for work are always in compliance with the security standards of the Contractor. If there are technical failures that compromise the security of the services, the Contractor must seek technical support immediately, as well as notify the Contractor of any interruption that may affect the integrity of the data or services.# Minimum requirements for work equipment

**Active Personal Firewall: **The Contractor must ensure that the device used to provide the services is protected by an active personal firewall, configured to block unauthorized access and monitor suspicious network activity.

**Updated Antivirus and Anti-Malware: **The device must have robust and up-to-date antivirus and anti-malware software installed, capable of detecting and removing threats such as viruses, spyware, ransomware, Trojans and other forms of malware. Automatic updates and regular checks are recommended.

**EDR (Endpoint Detection and Response): **The device must have an EDR solution to continuously monitor activities and behaviors on the endpoint. EDR must be able to quickly detect, investigate, and respond to advanced threats or suspicious behavior, as well as record activity for future audits.

**Data Loss Prevention (DLP): **The Contractor must implement Data Loss Prevention (DLP) mechanisms to protect the Contractor’s sensitive data, ensuring that confidential information is not copied, shared or sent inappropriately. The DLP must monitor and block unauthorized transfers of information.

**Regular Software and Operating System Updates: **The Contractor’s device must always be updated with the latest security fixes, both for the operating system and for the software used in development. The Contractor must ensure that automatic updates are enabled and that any errors are corrected immediately.

**Access Control: **The Contractor must ensure that the device uses secure authentication methods, such as strong passwords, multi-factor authentication (MFA) or biometrics. Access to the device must be restricted to authorized personnel only, and any unauthorized access attempts must be blocked.

**Safe Development Environment: **The development environment used by the Contractor must be isolated from other personal activities and protected from external interference. Tools such as IDEs (Integrated Development Environments) and code repositories (such as Git) must be configured to follow security best practices, such as using SSH and multi-factor authentication (MFA).

**Physical Protection of the Device **The Contractor is responsible for ensuring the physical security of your device, preventing it from being accessed by third parties or left in unsafe locations. In case of loss or theft of the device, the Contractor must notify the Contractor immediately and take the necessary measures to protect the data.

Information Security Awareness and Training

All users of the Platform must receive information security training.

Information security training must be updated regularly.

Monitoring and Auditing

The security of the Platform is regularly monitored and audited.Monitoring and audit results are used to improve the Platform’s information security posture.

Compliance

This Policy complies with the following laws and regulations:

  • General Personal Data Protection Law (LGPD)
  • Brazilian Competition Defense Law (LDC)
  • Civil Rights Framework for the Internet
  • ISO/IEC 27000 Information Security Standards

Review and Update

This Policy must be reviewed and updated at least annually or whenever there are significant changes to the Platform or the security environment.

Application

Failure to comply with this Policy may result in disciplinary action, including termination of the contract.

Last updated on