Your master data in a vendor's hands demands more than a promise. It demands a certificate.
4MDG is ISO 27001 certified. Security taken seriously.
Information Security Management System certified to ISO/IEC 27001:2022, audited by Bureau Veritas, covering the implementation, support and development of our MDM (Master Data Management) solution. Access control, encryption, audit trail, incident management and continuity: requirements verified by an independent third party, not sales promises.
160 clients trust us
The certificate
Audited certification, with a declared scope.
Certificate issued by Bureau Veritas Certification Holding SAS — UK Branch to ZH Soluções Especialista Ltda., the legal name of 4MDG. The scope covers the Information Security Management System that supports the implementation, support and development of our master data management solution.
Validity depends on the continued and satisfactory operation of the management system, verified in periodic audits by the certification body. We can send the certificate in PDF and the statement of applicability upon request.
ISO/IEC 27001:2022
Information Security Management System
Scope
The Information Security Management System that supports the implementation, support and development of the master data management solution.
What this means for you
The IT vendor assessment gets shorter.
Procurement, legal, information security and audit ask for the same evidence in every contract. With a certified ISMS, most of that list is already prepared and verified by an independent third party.
Due diligence with evidence
The certificate, scope, statement of applicability and public policies cover most of your company's security questionnaire.
Basis for LGPD and GDPR
The ISMS controls support the technical and organizational measures required of personal data processors under both laws.
Discipline that lasts
Internal audits, risk analysis, indicators and periodic external audits keep the controls from existing only on paper in the first year.
Controls
How data is protected, in practice.
Controls are organized into the four themes of ISO/IEC 27001:2022 — organizational, people, physical and technological — and applied both to the platform and to the operation of our services.
Organizational
Published information security policy, with defined roles and responsibilities and periodic management review.
Risk management with identification, assessment, treatment and monitoring of action plans.
Information classification, asset management and acceptable use rules.
Security in the relationship with suppliers and subcontractors, including cloud providers.
Incident management with logging, classification, response, communication and lessons learned.
People
Background checks at hiring, confidentiality agreement and security responsibilities in contract.
Periodic training and awareness, with a specific track for those who handle customer data.
Formal onboarding, role change and offboarding process, with access revocation.
Remote work and device usage rules, applicable to in-house and allocated teams.
Physical
Perimeter and entry control at the office, with restricted areas and visitor logging.
Equipment protection, clear desk and clear screen, and secure disposal of media and documents.
Processing infrastructure on cloud providers with their own certifications and data center redundancy.
Technological
Encryption in transit and at rest, with key and secret management.
Authentication, role-based profiles, least privilege and environment segregation.
Logging, monitoring, tested backup and continuity and recovery plan.
Vulnerability management, version updates and secure development with code review.
Architecture
An architecture designed from security up.
Security is not a layer placed on top of the platform. It is in how environments are separated, how each client's data is isolated, how access is granted and how every change is recorded.
Isolation per client
Each client operates in its own environment, with segregated data and independent credentials. Test and production environments are separate, and real data is not used in testing.
Least privilege by default
Profiles by role, permissions by flow step and by field, with segregation of duties between who requests, who reviews and who approves the record.
Encryption and secrets
Traffic over TLS, data encrypted at rest, integration keys and credentials kept in a vault, never in code or spreadsheets.
Controlled integration
Authenticated APIs, scope-based permissions, usage limits and a record of every call exchanged with ERP, CRM and external sources.
Full traceability
Logs of authentication, queries and changes, with author, date, previous value and attached evidence — the trail auditors ask for.
Continuity
Cloud with redundancy, periodic backups with tested restore, monitoring and a recovery plan with agreed time targets.
Periodic intrusion testing
The platform undergoes periodic intrusion tests (pen tests), plus continuous vulnerability scanning. The goal is to find the flaw before someone outside does.
Real scope. Web application, integration APIs and the supplier and customer portal, including authentication, permissions and business rules.
Defined cycle. Run periodically and whenever there is a relevant architecture change, with retesting to confirm the fix.
Deadline-bound handling. Each finding is classified by severity, assigned an owner and a deadline, and tracked within the ISMS until closure.
Before going live. Secure development, code review and dependency analysis in the release cycle, not only in the annual test.
Privacy
LGPD and GDPR in handling your master data.
Supplier and customer records carry personal data: partner and representative tax IDs, identification documents, contact details, addresses. 4MDG acts as a processor of this data, handling it solely under the instructions of the controlling client.
How we handle it
Purpose and legal basis on record, with minimization: only the data required by the registration process enters the platform.
Access by profile and by field, with logs of who viewed, changed and approved each record.
Retention defined by contract, with return and deletion of data at the end of the relationship.
Incident notification to the controller within the deadlines set by contract and by law.
Public documents
ISO 27001 certificate, statement of applicability and security questionnaire responses are sent on request, under a confidentiality agreement when required.
Need security evidence to approve 4MDG as a supplier? We send the complete package to your compliance team.
Request the evidence packContact
Talk to our information security team.
Certificate, scope, policies and answers to your security questionnaire. We will contact you.
Av. Queiroz Filho, 1700, Torre E, Conjuntos 715 a 718
Vila Leopoldina, São Paulo, SP, 05319-000
Common questions