Institutional document

Information Security Policy

Last updated: August 2026.

Identification

This Policy describes how VGrid — a brand operated by Rafael Lotfi Marrocos Leite Ltda., trade name LM Consultoria, CNPJ (Brazilian tax registry) 41.737.358/0001-89, São Paulo, SP, Brazil — protects the confidentiality, integrity and availability of information under its responsibility, including this website, service channels and clients' confidential information. E-mail: contato@vgrid.com.br.

About this translation

The English and Spanish versions are translations provided for convenience. In the event of any divergence of interpretation, the Portuguese version published at https://vgrid.com.br/politica-de-seguranca-da-informacao/ prevails, without prejudice to applicable mandatory rules.

1. Purpose and scope

This Policy records how VGrid protects the confidentiality, integrity and availability of the information under its responsibility.

The scope covers this website, service channels (e-mail, forms and WhatsApp), the internal systems used in operations and confidential client information obtained in consulting engagements. We apply to ourselves the same standard we recommend to clients: security proportional to risk, with an identifiable owner and evidence.

2. Principles

Information security at VGrid follows five principles, aligned with the logic of ISO/IEC 27001 and ISO/IEC 27701:

  • Least privilege: each granted access is limited to what is strictly necessary for the role performed.
  • Confidentiality by default: client information only circulates through authorized channels and repositories, with contractual safeguards.
  • Risk proportionality: controls are sized according to the sensitivity of the information — personal data, confidential project data and credentials receive reinforced protection.
  • Named accountability: security has an owner. In a small, senior-led structure, accountability is not diluted into abstract committees.
  • Continuous improvement: incidents, near-misses and vendor changes feed the periodic review of this Policy.

3. Technical and organizational measures

The main measures currently in operation are:

  • Encryption in transit: all traffic on this website and its forms occurs under HTTPS/TLS.
  • Access control: multi-factor authentication on administrative accounts and individual access, with no shared credentials.
  • Data minimization: forms collect only the data necessary for the declared purpose, as described in the Privacy Policy.
  • Environment segregation: client project data is kept separate from the website's public systems.
  • Vendor management: infrastructure, database and communication providers are selected against criteria of security, confidentiality and contractual compliance, with assessment before activation.

4. Clients' confidential information

Information obtained in consulting engagements is handled under confidentiality agreements and accessed exclusively by the people directly involved in the project. It is not entered into external tools — including AI tools — without express authorization and adequate contractual safeguards, as detailed in the AI Governance Policy.

At the end of each engagement, retention and the return or disposal of materials follow what is contractually agreed with the client.

5. Personal data

The processing of personal data complies with the LGPD and is described, by purpose and legal basis, in this website's Privacy Policy. The security measures described here also protect the personal data collected through the forms, e-mail and service channels.

6. Incident management

Security incidents are handled with priority: containment, impact assessment, correction and recording of lessons learned. When an incident involves personal data and may result in relevant risk or harm to data subjects, notification to the competent authority and to data subjects will follow the timeframes and conditions set out in the LGPD.

If you identify a vulnerability on this website or suspicious behavior in any VGrid channel, report it to contato@vgrid.com.br. Good-faith security reports are welcome and handled confidentially.

7. Roles and responsibilities

Rafael Lotfi Marrocos Leite, founding partner, is responsible for approving this Policy, managing security risks and incidents, and assessing vendors. Direct channel: contato@vgrid.com.br.

8. Review and effectiveness

This Policy is reviewed whenever a relevant change occurs in operations — new vendors, new systems or lessons learned from incidents — and, at a minimum, annually. Relevant changes take effect upon publication on this page, with the reference date updated, and the same revision is applied simultaneously to the English and Spanish versions. In the event of divergence, the Portuguese version published at https://vgrid.com.br/politica-de-seguranca-da-informacao/ prevails.

Questions about this policy?

Write to contato@vgrid.com.br or use the contact page — we respond directly.