Kockpit · GLIP
Information Security Policy
Governance, technical controls and practices adopted to protect the information assets of GLIP, Kockpit and their clients.
Last updated: June/2026
I. Security Guidelines
Information security is a foundational pillar of governance at GLIP and Kockpit. We apply rigorous administrative, technical and physical safeguards, aligned with industry best practices, to protect digital assets against unauthorized access, destruction, loss, accidental alteration or unlawful processing.
II. Technical Measures Implemented
- Encryption: data in transit and at rest is protected by industry-standard algorithms, notably TLS 1.2+ for traffic and AES-256 for storage.
- Restricted access control: least-privilege principle, so that only strictly authorized staff, authenticated with multi-factor authentication (MFA), have access to critical environments.
- Environment segregation: logical separation between development, staging and production, with distinct credentials and perimeters.
- Monitoring and auditing: continuous vulnerability scanning, periodic penetration tests and detailed audit logs, retained for periods consistent with legal obligations.
- Backups and continuity: formal backup, restore and business-continuity policies, with periodic recovery tests.
III. Governance and Awareness
We maintain an internal information-security governance program, with formal policies, periodic staff training, role-based access control (RBAC) and recurring review of privileged access.
IV. Incident Management
We have a formal security-incident response process covering identification, containment, eradication, recovery and communication. Incidents involving personal data that pose significant risk or harm to data subjects will be reported to the Brazilian Data Protection Authority (ANPD) and to affected data subjects, as required by article 48 of the LGPD.
V. Vulnerability Reporting
Security researchers, clients and third parties may responsibly report vulnerabilities through security@glip.com.br. We accept no responsibility for unauthorized testing in production environments.
Questions about this document? Reach out to GLIP/Kockpit's Data Protection Officer (DPO): . dpo@glip.com.br.
