Information Security Policy
This English version is a convenience translation. In case of any discrepancy, the Portuguese version prevails.
March 2026 — Version 1.0
Document Control
| Document Title | Information Security Policy |
| Owner | Chief Compliance & Technology Officer |
| Classification | Public |
| Version | 1.0 |
| Effective Date | March 2026 |
| Review Cycle | Annual (or upon material change) |
1. Purpose
This Information Security Policy ("Policy") establishes the security controls, standards, and procedures governing all information assets, systems, and infrastructure of DECADE WEALTH MANAGEMENT LTDA. Its purpose is to protect the confidentiality, integrity, and availability of data processed by the company's entities, in compliance with applicable Brazilian and international regulatory requirements.
2. Identity and Access Management
2.1 Authentication Framework
All user authentication to the systems of DECADE WEALTH MANAGEMENT LTDA is centralized through a corporate identity provider (IdP), with Single Sign-On (SSO) across corporate and production systems. Multi-factor authentication (MFA) is mandatory for all user accounts without exception.
Client-facing authentication flows follow financial-grade security profiles, incorporating token binding and protections against replay and interception attacks.
2.2 Privileged Access and the Principle of Least Privilege
DECADE WEALTH MANAGEMENT LTDA applies the principle of least privilege across all systems. Access grants are reviewed quarterly and require managerial approval. Privileged actions on production systems require explicit justification and are logged for audit purposes.
3. Network Security
3.1 Network Isolation
Production workloads operate within private networks, with no direct internet exposure. Segmentation is enforced through stateful firewalls that follow a default-deny posture: only explicitly authorized traffic is permitted.
3.2 Secure Remote Access
Remote employees access internal resources exclusively through encrypted channels with strong authentication, ensuring that no production service is exposed to the public internet.
4. Data Protection and Encryption
4.1 Encryption at Rest
All data at rest is encrypted across the infrastructure of DECADE WEALTH MANAGEMENT LTDA:
- Endpoint devices: all company-provided laptops and workstations enforce full-disk encryption, ensuring that data remains protected in the event of device loss or theft.
- Databases: all production databases enforce encryption at rest using AES-256 (or equivalent), with customer-managed keys.
- Object storage and backups: all object-storage data, including backup files, is encrypted at rest using server-side encryption with customer-managed keys.
4.2 Encryption in Transit
All communications between services, both internal and external, are encrypted in transit:
- Mutual TLS (mTLS) is enforced for all service-to-service communication, preventing man-in-the-middle attacks and unauthorized service impersonation.
- Short-lived access tokens are used for authorization between services, minimizing the blast radius of any potential token compromise.
- All externally facing endpoints enforce TLS 1.2 or higher, with strong cipher suites.
5. Backup and Disaster Recovery
5.1 Backup Strategy
DECADE WEALTH MANAGEMENT LTDA maintains a comprehensive backup regime designed for resilience against data loss, ransomware, and infrastructure failures:
- Daily automated backups of all production databases and critical data stores are performed.
- Backups are kept isolated from the production environment and geographically redundant, so that a compromise of the production environment does not grant access to backup data.
- Backup integrity is verified through automated checksums, and periodic restore tests are performed to validate recoverability.
5.2 Recovery Objectives
Recovery Point Objective (RPO) and Recovery Time Objective (RTO) targets are defined by data classification level and reviewed annually. Disaster recovery procedures are documented, tested at least once a year, and updated after each test cycle.
6. Secure Software Development Lifecycle
DECADE WEALTH MANAGEMENT LTDA enforces change-management controls over production codebases, including mandatory review by multiple approvers before any deployment, protection of production branches, and automated security checks (static analysis and dependency vulnerability scanning) in the continuous integration and delivery pipeline. No individual may unilaterally deploy code to production.
7. Logging, Monitoring, and Incident Response
7.1 Logging and Audit Trail
All authentication events, access control decisions, privileged actions, and changes to security configurations are logged to a centralized, tamper-resistant logging platform. Logs are retained for a minimum period consistent with applicable regulatory requirements.
7.2 Monitoring and Alerting
Automated monitoring is configured to detect anomalous activity, including but not limited to: unusual authentication patterns, unauthorized access attempts, privilege escalation, and data exfiltration indicators. Alerts are routed to the security operations team for triage and response.
7.3 Incident Response
DECADE WEALTH MANAGEMENT LTDA maintains a documented Incident Response Plan, reviewed annually, covering identification, containment, eradication, recovery, and post-incident review. Material security incidents are reported to the competent regulatory authorities (CVM, BCB, ANPD) within the timeframes prescribed by applicable regulation.
8. Third-Party and Vendor Security
All third-party service providers with access to the data or systems of DECADE WEALTH MANAGEMENT LTDA undergo security due diligence prior to engagement. Vendor contracts include data protection obligations, breach notification requirements, and the right to audit. Ongoing vendor compliance is reviewed at least annually.
9. Regulatory Alignment
This Policy has been designed to meet the requirements of, among others:
- BCB Resolution 4893/2021 — Cybersecurity policy requirements for institutions authorized by the Central Bank of Brazil.
- CVM Resolution 175 — Operational and compliance requirements for regulated securities entities.
- LGPD (Law 13.709/2018) — Data protection and privacy obligations, including technical and organizational security measures.
- ANBIMA Self-Regulation Code — Best practices for asset management and distribution, including information security controls.
- ISO/IEC 27001 — Referenced as a guiding framework for information security management, although formal certification has not yet been pursued.
10. Policy Governance
10.1 Roles and Responsibilities
The Chief Compliance & Technology Officer is the designated owner of this Policy and is responsible for its maintenance, enforcement, and periodic review. All employees are responsible for complying with this Policy and promptly reporting suspected security incidents.
10.2 Review and Amendment
This Policy is reviewed at least annually, or whenever a material change occurs in the threat landscape, the regulatory environment, or the company's technology infrastructure. Amendments require approval from the Board of Directors.
10.3 Exceptions
Any exception to this Policy must be formally documented, assessed for risk, approved by the Policy owner, and subject to compensating controls. Exceptions are reviewed quarterly and expire after a maximum of 12 months, unless renewed.
11. Sanctions
Violations of this Policy may result in disciplinary action, including termination of employment or service contracts, and referral to the competent legal authorities where required by law.
Privacy Policy · Terms & Conditions · Information Security · Suitability · PLD/FTP · Código de Ética · Investimentos Pessoais · Formulário de Referência