ISO/IEC 27001:2022 Bureau Veritas audit LGPD and GDPR

Your master data in a vendor's hands demands more than a promise. It demands a certificate.

4MDG is ISO 27001 certified. Security taken seriously.

Information Security Management System certified to ISO/IEC 27001:2022, audited by Bureau Veritas, covering the implementation, support and development of our MDM (Master Data Management) solution. Access control, encryption, audit trail, incident management and continuity: requirements verified by an independent third party, not sales promises.

160 clients trust us

NestléCarrefourGeneral MotorsHeinekenWhirlpoolHershey'sDasaSoftysJactoPanasonicIntelbrasiFoodNestléCarrefourGeneral MotorsHeinekenWhirlpoolHershey'sDasaSoftysJactoPanasonicIntelbrasiFood

The certificate

Audited certification, with a declared scope.

Certificate issued by Bureau Veritas Certification Holding SAS — UK Branch to ZH Soluções Especialista Ltda., the legal name of 4MDG. The scope covers the Information Security Management System that supports the implementation, support and development of our master data management solution.

Validity depends on the continued and satisfactory operation of the management system, verified in periodic audits by the certification body. We can send the certificate in PDF and the statement of applicability upon request.

ISO/IEC 27001:2022

Information Security Management System

Organismo certificador Bureau Veritas Certification Holding SAS — UK Branch
Certificate number IND.26.3035/IS/U
Original certification 25 June 2026
Validade 24 June 2029
Entidade certificada ZH Soluções Especialista Ltda. (4MDG)

Scope

The Information Security Management System that supports the implementation, support and development of the master data management solution.

What this means for you

The IT vendor assessment gets shorter.

Procurement, legal, information security and audit ask for the same evidence in every contract. With a certified ISMS, most of that list is already prepared and verified by an independent third party.

Due diligence with evidence

The certificate, scope, statement of applicability and public policies cover most of your company's security questionnaire.

Basis for LGPD and GDPR

The ISMS controls support the technical and organizational measures required of personal data processors under both laws.

Discipline that lasts

Internal audits, risk analysis, indicators and periodic external audits keep the controls from existing only on paper in the first year.

Controls

How data is protected, in practice.

Controls are organized into the four themes of ISO/IEC 27001:2022 — organizational, people, physical and technological — and applied both to the platform and to the operation of our services.

Organizational

Published information security policy, with defined roles and responsibilities and periodic management review.

Risk management with identification, assessment, treatment and monitoring of action plans.

Information classification, asset management and acceptable use rules.

Security in the relationship with suppliers and subcontractors, including cloud providers.

Incident management with logging, classification, response, communication and lessons learned.

People

Background checks at hiring, confidentiality agreement and security responsibilities in contract.

Periodic training and awareness, with a specific track for those who handle customer data.

Formal onboarding, role change and offboarding process, with access revocation.

Remote work and device usage rules, applicable to in-house and allocated teams.

Physical

Perimeter and entry control at the office, with restricted areas and visitor logging.

Equipment protection, clear desk and clear screen, and secure disposal of media and documents.

Processing infrastructure on cloud providers with their own certifications and data center redundancy.

Technological

Encryption in transit and at rest, with key and secret management.

Authentication, role-based profiles, least privilege and environment segregation.

Logging, monitoring, tested backup and continuity and recovery plan.

Vulnerability management, version updates and secure development with code review.

Architecture

An architecture designed from security up.

Security is not a layer placed on top of the platform. It is in how environments are separated, how each client's data is isolated, how access is granted and how every change is recorded.

Isolation per client

Each client operates in its own environment, with segregated data and independent credentials. Test and production environments are separate, and real data is not used in testing.

Least privilege by default

Profiles by role, permissions by flow step and by field, with segregation of duties between who requests, who reviews and who approves the record.

Encryption and secrets

Traffic over TLS, data encrypted at rest, integration keys and credentials kept in a vault, never in code or spreadsheets.

Controlled integration

Authenticated APIs, scope-based permissions, usage limits and a record of every call exchanged with ERP, CRM and external sources.

Full traceability

Logs of authentication, queries and changes, with author, date, previous value and attached evidence — the trail auditors ask for.

Continuity

Cloud with redundancy, periodic backups with tested restore, monitoring and a recovery plan with agreed time targets.

Periodic intrusion testing

The platform undergoes periodic intrusion tests (pen tests), plus continuous vulnerability scanning. The goal is to find the flaw before someone outside does.

Real scope. Web application, integration APIs and the supplier and customer portal, including authentication, permissions and business rules.

Defined cycle. Run periodically and whenever there is a relevant architecture change, with retesting to confirm the fix.

Deadline-bound handling. Each finding is classified by severity, assigned an owner and a deadline, and tracked within the ISMS until closure.

Before going live. Secure development, code review and dependency analysis in the release cycle, not only in the annual test.

Request the latest pen test summary →

Privacy

LGPD and GDPR in handling your master data.

Supplier and customer records carry personal data: partner and representative tax IDs, identification documents, contact details, addresses. 4MDG acts as a processor of this data, handling it solely under the instructions of the controlling client.

How we handle it

Purpose and legal basis on record, with minimization: only the data required by the registration process enters the platform.

Access by profile and by field, with logs of who viewed, changed and approved each record.

Retention defined by contract, with return and deletion of data at the end of the relationship.

Incident notification to the controller within the deadlines set by contract and by law.

Public documents

Information security policy → Privacy policy → Terms of use →

ISO 27001 certificate, statement of applicability and security questionnaire responses are sent on request, under a confidentiality agreement when required.

Need security evidence to approve 4MDG as a supplier? We send the complete package to your compliance team.

Request the evidence pack

Contact

Talk to our information security team.

Certificate, scope, policies and answers to your security questionnaire. We will contact you.

+55 11 4113-2510 atendimento@4mdg.com.br

Av. Queiroz Filho, 1700, Torre E, Conjuntos 715 a 718
Vila Leopoldina, São Paulo, SP, 05319-000

Your data is processed in accordance with the LGPD.

Common questions

Questions about ISO 27001 and security