About VGrid

A boutique consultancy with a single thesis: AI must be governable

We work with a small number of organisations at a time, in depth, on the governance of artificial intelligence — supported by cybersecurity, privacy and monitoring as sustaining layers.

Who is VGrid?

VGrid is a boutique consultancy specialising in corporate AI governance, AI security and AI compliance. It is led by Rafael Lotfi Marrocos Leite, Founder and CEO, who works as CISO and DPO for client organisations and holds Lead Implementer and Lead Auditor credentials for ISO/IEC 27001, ISO/IEC 27701 and ISO/IEC 42001. Engagements are delivered in Portuguese, English and Spanish for clients in Latin America, Europe and the United States.

How we work

Depth over volume

A limited client portfolio, with senior practitioners on the work rather than on the proposal only.

Evidence-driven

Every recommendation ends in something inspectable: a control, a record, a metric or a documented decision.

Framework-anchored

ISO/IEC 42001, ISO/IEC 23894, NIST AI RMF, the EU AI Act and applicable data protection law, applied to your context.

Honest about limits

We do not issue certifications, guarantee compliance or sell tooling. We build governance that holds up under scrutiny.

Frequently asked questions

In which languages and regions does VGrid operate?

Engagements are delivered in Portuguese, English and Spanish, for organisations in Latin America, Europe and the United States. Regulatory work is scoped per jurisdiction, with local counsel involved where legal opinion is required.

Does VGrid resell software?

Our advisory work is independent. Where a technology partner is relevant to a client's control objectives, the relationship is disclosed and the recommendation remains grounded in the client's requirements.

Talk to the team

Bring us the AI governance question you are stuck on.