1. Introduction
Legitimuz Tecnologia Ltda. is a Brazilian company specializing in KYC solutions, biometric authentication, fraud prevention, and anti-money laundering, operating in the regulated iGaming sector and related segments.
This Information Security Policy (ISP) consolidates, in public language, the principles, commitments, and practices that govern the handling, protection, and governance of information under Legitimuz's responsibility.
This public version is intended for clients undergoing due diligence, business partners, data subjects, and other stakeholders who need to understand Legitimuz's level of maturity in information security.
The detailed internal policy is maintained in Legitimuz's Information Security Management System (ISMS), and access is restricted to employees, service providers, and authorized auditors.
2. Certifications and Regulatory Framework
Legitimuz maintains an Information Security Management System certified by an accredited independent body, and structures its operations in accordance with the main standards and regulations applicable to its sector.
2.1. Current Certifications
- ABNT NBR ISO/IEC 27001:2022 — Information Security Management System, with certification issued by an accredited certification body and annual maintenance audit;
- ISO/IEC 30107-3 (iBeta) — Biometric Presentation Attack Detection tests, applicable to the biometric components of the facial authentication platform.
2.2. Applicable regulatory framework
Legitimuz continuously monitors the applicable regulatory framework and adapts its controls to relevant regulatory updates.
- Law No. 13.709/2018 (LGPD);
- Law No. 15.352/2026;
- Law No. 15.211/2025 (ECA Digital);
- Law No. 14,790/2023 and SPA/MF Ordinance No. 722/2024;
- Law No. 9,613/1998 and COAF Resolution No. 1,143/2024;
- Data protection equivalence between Brazil and the European Union;
- Regulation (EU) 2016/679 (GDPR).
3. Principles of Information Security at Legitimuz
- Confidentiality: to guarantee access only to authorized individuals;
- Integrity: to preserve the accuracy and completeness of the information;
- Availability: to ensure access to information when necessary;
- Privacy: full compliance with the LGPD and applicable regulations;
- Lesser privilege: access granted according to role and responsibility;
- Security by design: incorporate security and privacy from the development stage;
- Defense in depth: multiple layers of control for risk mitigation;
- Continuous improvement: constant improvement of security controls.
4. Scope and Applicability
This policy applies to employees, service providers, suppliers, and third parties who have access to Legitimuz's information systems, data, and assets.
5. Governance Structure
- Senior management: approves policies and defines strategies;
- DPO and Compliance Officer: responsible for regulatory compliance;
- Information Security Area: daily operation of the ISMS;
- Information Security and Privacy Committee: risk monitoring and indicators;
- Area managers: application of the guidelines;
- Employees and third parties: compliance with the policy.
6. Information Security Guidelines
6.1. Classification and protection of information
The information handled by Legitimuz is classified according to its sensitivity, and the applicable controls vary depending on the classification level.
6.2. Access control
Access to systems, applications, and data is granted based on the principle of least privilege, upon formal request and competent approval.
6.3. Protection of personal data
- Mapping of personal data processing practices;
- Maintenance of Treatment Operation Records (ROPA);
- Conducting RIPD/DPIA;
- Responding to requests from data subjects;
- Prior assessment of legal bases;
- Cryptography and access controls;
- Evaluation of international transfers.
6.4. Risk Management
Legitimuz maintains a formal methodology for managing information security risks.
6.5. Incident Management
Legitimuz maintains a formal incident response plan, including detection, containment, eradication, and recovery.
6.6. Business continuity and disaster recovery
The company maintains a disaster recovery plan and business continuity strategies for critical services.
6.7. Secure Development
The development cycle incorporates security practices, code review, and periodic penetration testing.
6.8. Security in cloud services
Legitimuz uses internationally recognized cloud providers with certified security controls.
6.9. Awareness, education and training
Regular awareness and training programs in information security are conducted.
6.10. Supplier Management
Suppliers and third parties undergo a formal information security risk assessment.
6.11. Remote work and mobility
Legitimuz maintains specific controls for remote access, including multi-factor authentication and encrypted connections.
7. Audits, Monitoring and Continuous Improvement
Legitimuz's ISMS is subject to regular internal and external audits, conducted by independent consulting firms and certification bodies.
8. Commitment from Senior Management
- Approval and dissemination of this policy;
- Provision of resources necessary for the ISMS;
- Promoting an organizational culture of safety;
- Periodic monitoring of ISMS performance;
- Garantia da independência da função de segurança da informação.
9. Contact Channels
| Purpose | Channel |
|---|---|
| DPO — exercising rights and questions about personal data | [email protected] |
| Security incident reporting | [email protected] |
| Due diligence and certifications | [email protected] |
10. Validity and Review
This policy is reviewed at least annually, or whenever there are significant changes in the regulatory context, organizational structure, or threat environment.
Legitimuz Tecnologia Ltda.
legitimuz.com
Public document — Version 1.0 — May 2026