Compliance & Governance

Systems Aligned with the Requirements of the ISO Standards

We structure our processes, controls and policies in conformity with the requirements of the ISO 27001, 27701, 20000-1, 42001 and 37001 standards — ensuring security, privacy, governance and ethics in the services we deliver.

Transparency about our positioning. Centriu is not a certified company and does not use seals or logos that suggest official certification. We carry out internal adjustments and implement processes, controls, policies and best practices aligned with the requirements of the ISO standards cited on this page. This is a matter of operational compliance and continuous improvement, and not certification granted by an accredited body.
ISO Standard27001

Information Security Structured in Accordance with ISO/IEC 27001

Information Security Management System (ISMS)

ISO/IEC 27001 is the international reference standard for information security management. Its goal is to establish, implement, maintain and continually improve a system that protects the confidentiality, integrity and availability of information. Centriu has structured its internal processes in conformity with the requirements of the standard, adopting a risk-based approach to protect the data under its responsibility.

Benefits for customers

  • Greater protection of the information and data entrusted by customers to the platform.
  • Reduced risk of incidents, leaks and service unavailability.
  • An organized and timely response to any security incidents.
  • Greater predictability, reliability and transparency in the relationship with customers and partners.

Practices adopted by Centriu

  • A formalized Information Security Policy that is reviewed periodically.
  • Risk management with continuous identification, assessment and treatment of threats.
  • Access controls based on the principle of least privilege and need-to-know.
  • Encryption of data in transit and at rest, and segregation of environments.
  • Log recording, audit trails and monitoring of security events.
  • An incident management process with classification, response and lessons learned.
  • Verified backups and restore testing.
  • Periodic internal audits and a continuous improvement cycle for controls.

Centriu has developed and maintains its internal information security processes in conformity with the requirements of the ISO/IEC 27001 standard, adopting controls, policies and best practices aligned with its guidelines. The activities described refer to internal operational adjustments and do not constitute, nor should they be interpreted as, certification issued by an accredited certification body.

Information security structured in accordance with the requirements of ISO/IEC 27001.
ISO Standard27701

Information Privacy Aligned with ISO/IEC 27701 and the LGPD

Privacy Information Management System (PIMS)

ISO/IEC 27701 extends information security management to the protection of personal data, serving as a reference for a Privacy Information Management System. Centriu has structured its processes in conformity with the principles of the standard and with the Brazilian General Data Protection Law (LGPD — Law No. 13.709/2018) and the Brazilian Internet Civil Framework (Law No. 12.965/2014), reinforcing the responsible processing of personal data.

Benefits for customers

  • Processing of personal data based on recognized privacy principles.
  • Greater clarity about how data is collected, used and protected.
  • Support for customers in complying with the obligations set out in the LGPD.
  • Mechanisms to fulfill the rights of data subjects.

Practices adopted by Centriu

  • Privacy by design and by default.
  • Mapping of personal data and record of processing activities (ROPA).
  • Defined legal bases and observance of the minimization and purpose principles.
  • Access control to personal data and segregation by role and need.
  • Data governance with defined responsibilities and a privacy channel.
  • Procedures to fulfill the rights of data subjects within appropriate timeframes.
  • Management of incidents involving personal data and impact assessment where applicable.
  • Guidelines for the relationship with processors and for international transfers.

Centriu adopts privacy controls and practices aligned with the requirements of the ISO/IEC 27701 standard and with the provisions of the Brazilian General Data Protection Law (Law No. 13.709/2018) and the Brazilian Internet Civil Framework (Law No. 12.965/2014). This is an internal operational adjustment regarding privacy and does not constitute certification granted by an accredited body.

Privacy and protection of personal data aligned with ISO/IEC 27701 and the LGPD.
ISO Standard20000-1

IT Service Management in Accordance with ISO/IEC 20000-1

Service Management System (SMS)

ISO/IEC 20000-1 is the international standard for information technology service management. Its purpose is to ensure the delivery of services with quality, consistency and continuous improvement. Centriu has structured the operation of its services in conformity with the principles of the standard, standardizing processes to ensure availability, stability and predictability for customers.

Benefits for customers

  • More stable, available and predictable services day to day.
  • Agile and organized handling of incidents and requests.
  • Controlled changes, reducing the risk of disruption.
  • Transparent communication about service levels and continuity.

Practices adopted by Centriu

  • Service quality management with service-level indicators and targets (SLAs/SLOs).
  • Incident management with logging, prioritization and structured resolution.
  • Change management with risk assessment, approval and controlled windows.
  • Operational continuity and service recovery plans.
  • Continuous monitoring of platform availability and performance.
  • Capacity management to keep pace with demand growth.
  • Standardization and documentation of internal operational processes.
  • Periodic satisfaction assessment and a continuous improvement cycle.

Centriu organizes and operates its technology services in conformity with the requirements of the ISO/IEC 20000-1 standard, maintaining standardized service management processes. The practices described here correspond to internal operational adjustments and do not represent certification issued by an accredited certification body.

IT service management structured in accordance with the requirements of ISO/IEC 20000-1.
ISO Standard42001

Artificial Intelligence Governance in Accordance with ISO/IEC 42001

Artificial Intelligence Management System (AIMS)

ISO/IEC 42001 is the first international standard dedicated to the management of Artificial Intelligence systems. It guides the responsible, ethical and transparent use of AI, with governance, risk control and human oversight. Centriu has structured the use of Artificial Intelligence in its products in conformity with the principles of the standard, prioritizing trustworthy, people-centered AI.

Benefits for customers

  • Use of Artificial Intelligence in a responsible, ethical and transparent way.
  • Greater trust in how AI features support decisions and operations.
  • Reduced risks associated with bias and inappropriate outcomes.
  • Clarity about the presence of AI and the human oversight applied.

Practices adopted by Centriu

  • AI governance with defined roles, responsibilities and usage guidelines.
  • A policy for the ethical and responsible use of Artificial Intelligence.
  • Risk and impact assessment of AI systems (AIIA where applicable).
  • Measures for the identification and mitigation of bias.
  • Transparency and labeling regarding the use of AI features.
  • Traceability and recording of AI-assisted decisions.
  • Human oversight at critical points of the flow (human-in-the-loop).
  • Care for the security, privacy and integrity of models and data.

Centriu develops and operates Artificial Intelligence features in conformity with the principles and requirements of the ISO/IEC 42001 standard, adopting practices of governance, transparency and human oversight. Such measures constitute an internal operational adjustment and do not configure certification granted by an accredited body.

Responsible and governed Artificial Intelligence in accordance with the requirements of ISO/IEC 42001.
ISO Standard37001

Integrity and Anti-Bribery in Accordance with ISO 37001

Anti-Bribery Management System (ABMS)

ISO 37001 is the international standard focused on the prevention, detection and handling of bribery and corruption practices. Its goal is to strengthen integrity and ethics in the organization’s relationships. Centriu has structured its internal controls in conformity with the principles of the standard, reinforcing a culture of integrity, transparency and compliance.

Benefits for customers

  • A business relationship guided by integrity, ethics and transparency.
  • Greater assurance regarding the soundness of internal processes.
  • Mechanisms for the prevention of fraud and corruption practices.
  • A reporting channel available for communicating inappropriate conduct.

Practices adopted by Centriu

  • An anti-bribery policy and a code of business conduct and ethics.
  • Internal controls for the prevention of fraud and acts of corruption.
  • Guidelines on gifts, hospitality and conflicts of interest.
  • Assessment and monitoring of integrity risks.
  • A reporting (whistleblowing) channel with confidential handling and non-retaliation.
  • Integrity due diligence in relationships with third parties.
  • Corporate governance with clearly defined responsibilities.
  • Continuous training and awareness about integrity.

Centriu maintains internal controls for integrity and bribery prevention in conformity with the requirements of the ISO 37001 standard, including an anti-bribery policy, governance and a reporting channel. The measures described represent an internal operational adjustment and do not constitute certification issued by an accredited certification body.

Corporate integrity and anti-bribery controls in accordance with the requirements of ISO 37001.
Continuous improvement

Commitment to International Best Practices

Centriu has structured its processes on the basis of internationally recognized standards and continuously seeks to evolve its internal controls. Alignment with these standards strengthens the security, privacy, governance and reliability of our services.

Processes structured on the basis of internationally recognized standards.
Continuous evolution of internal controls and the best practices adopted.
Security, privacy, governance and reliability as the pillars of our services.
Transparency: we do not claim to hold certifications that were not issued by accredited bodies.

Our commitment is to continuous improvement and to the adoption of the best market practices. The initiatives described on this page represent internal operational adjustments, aligned with the requirements of the standards mentioned, and do not constitute certification granted by an accredited certification body.

Legal notice: the references to the ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 20000-1, ISO/IEC 42001 and ISO 37001 standards on this page indicate that Centriu has developed its processes in conformity with the respective requirements, through internal operational adjustments and the adoption of best practices. Centriu does not declare that it holds ISO certification and does not use seals, logos or any elements that suggest official certification. Any certifications may only be issued by duly accredited certification bodies.