1. Purpose
This Information Security and Cybersecurity Policy sets out the principles and guidelines adopted by TroqPay to protect information, personal data, technology assets, and services under its responsibility against unauthorized access, use, alteration, disclosure, destruction, or unavailability.
The Policy guides the prevention, identification, and handling of security risks and incidents, promotes service continuity, defines responsibilities, and seeks to preserve the confidentiality, integrity, availability, authenticity, and traceability of information.
TroqPay is a financial technology company that provides a platform, software, APIs, checkout, webhooks, reconciliation, automation, intelligence, and technology integrations. TroqPay is not a bank, financial institution, payment institution, or direct provider of regulated financial services. Where such services are available, they are performed by duly qualified or authorized partners, as applicable.
This Policy contains public guidelines. Internal procedures, architecture, configurations, credentials, vendors, monitoring parameters, test results, vulnerabilities, and response plans whose disclosure could increase security risk are confidential and are not part of this document.
Company: Troq Soluções Digitais LTDA, Brazilian CNPJ 32.231.982/0001-19.
Version: 1.0.
Effective date: August 23, 2026.
Approval: TroqPay Management.
Security: security@troqpay.com.
Privacy and support: help@troqpay.com.
2. Legal and regulatory references
This Policy considers, as applicable to TroqPay's role, Brazilian laws governing data protection, internet use, security, confidentiality, and incident reporting, as well as contractual obligations to customers, vendors, and partners.
Where relevant, it also considers sector-specific rules applicable to partner institutions responsible for financial, payment, or virtual-asset services, including BCB Resolution No. 85/2021, as amended, and security standards appropriate to TroqPay's size, business model, activities, and risks.
References to Central Bank of Brazil rules or to obligations of regulated institutions do not mean that TroqPay represents itself as an institution authorized or supervised by that authority. Such rules are considered when they apply to competent partners, arise from contractual obligations, or provide a proportional benchmark for good practices.
- Law No. 13,709/2018, the Brazilian General Data Protection Law (LGPD).
- Law No. 12,965/2014, the Brazilian Civil Rights Framework for the Internet, and its regulations.
- ANPD Resolution No. 15/2024 on personal-data security incident reporting.
- Security, confidentiality, data-protection, continuity, and incident-reporting obligations established by law or contract.
3. Definitions
Information asset: data, document, system, application, device, service, credential, knowledge, or another resource relevant to TroqPay's activities.
Personal data: information relating to an identified or identifiable natural person, as defined by the LGPD.
Security incident: a confirmed event that compromises or may compromise the confidentiality, integrity, availability, authenticity, or traceability of information or services.
Confidential information: nonpublic information whose unauthorized access or disclosure may harm TroqPay, customers, data subjects, partners, vendors, or third parties.
Competent partner: an institution or provider responsible for a financial, regulated, or critical step of an operation within its legal, regulatory, and contractual authority.
Third party: a vendor, service provider, partner, consultant, or person that processes information or accesses TroqPay assets.
4. Scope
This Policy applies to TroqPay officers, employees, contractors, vendors, and partners who have access to information, systems, services, or technology environments under the company's responsibility.
Where applicable, these guidelines also cover customers and platform users, particularly regarding credential protection, lawful use of services, and reporting of suspected incidents.
Contracts, Terms of Use, the Privacy Policy, internal standards, and partner rules may establish additional security obligations based on the nature and risk of the relationship.
5. Principles
- Confidentiality: information is accessible only to authorized people and systems for legitimate purposes.
- Integrity: information is protected against unauthorized alteration, destruction, or processing.
- Availability: information and services are available to authorized people when needed, subject to contractual conditions and operational risks.
- Authenticity: the identity of users, systems, and processes involved in accessing or processing information is verified.
- Traceability: appropriate records support monitoring, investigations, audits, and accountability.
- Least privilege: access is limited to what is necessary to perform authorized duties.
- Prevention and proportionality: safeguards reflect asset criticality, data sensitivity, the state of technology, and identified risks.
- Privacy and accountability: data is protected throughout the product lifecycle, and evidence is maintained in line with applicable obligations.
6. Governance and responsibilities
TroqPay Management is responsible for approving this Policy, supporting its implementation, and ensuring resources appropriate to the company's size, risks, and business model.
The functions responsible for security, technology, privacy, risk, and operations must coordinate to establish and review controls, assess risks, oversee material changes, coordinate incident response, promote awareness, and maintain records needed for accountability.
Employees, contractors, and third parties must comply with this Policy, use assets only for authorized purposes, protect credentials, and promptly report situations that may create security risk.
Each competent partner remains responsible for the controls, systems, regulatory obligations, and incidents related to the services it performs. TroqPay cooperates with those partners within the limits of its role, applicable law, and contracts.
7. Risk and information-asset management
TroqPay maintains a proportional process to identify relevant assets, assess threats and vulnerabilities, estimate impacts, and define security risk treatments.
Assets must have a designated owner and be protected throughout their lifecycle, from creation or procurement through disposal, termination, or replacement.
Information must be classified according to sensitivity, criticality, legal obligations, and potential impact. Classification guides access, use, sharing, storage, transmission, retention, and disposal.