Security

Information Security and Cybersecurity Policy

TroqPay guidelines for information protection, risk management, service continuity, and incident response.

Last updated: August 23, 2026
Troq Soluções Digitais LTDA · CNPJ 32.231.982/0001-19
Governance

Governance, scope, and risk management

Principles and responsibilities that guide the protection of TroqPay information and services.

1. Purpose

This Information Security and Cybersecurity Policy sets out the principles and guidelines adopted by TroqPay to protect information, personal data, technology assets, and services under its responsibility against unauthorized access, use, alteration, disclosure, destruction, or unavailability.

The Policy guides the prevention, identification, and handling of security risks and incidents, promotes service continuity, defines responsibilities, and seeks to preserve the confidentiality, integrity, availability, authenticity, and traceability of information.

TroqPay is a financial technology company that provides a platform, software, APIs, checkout, webhooks, reconciliation, automation, intelligence, and technology integrations. TroqPay is not a bank, financial institution, payment institution, or direct provider of regulated financial services. Where such services are available, they are performed by duly qualified or authorized partners, as applicable.

This Policy contains public guidelines. Internal procedures, architecture, configurations, credentials, vendors, monitoring parameters, test results, vulnerabilities, and response plans whose disclosure could increase security risk are confidential and are not part of this document.

Company: Troq Soluções Digitais LTDA, Brazilian CNPJ 32.231.982/0001-19.

Version: 1.0.

Effective date: August 23, 2026.

Approval: TroqPay Management.

Security: security@troqpay.com.

Privacy and support: help@troqpay.com.

3. Definitions

Information asset: data, document, system, application, device, service, credential, knowledge, or another resource relevant to TroqPay's activities.

Personal data: information relating to an identified or identifiable natural person, as defined by the LGPD.

Security incident: a confirmed event that compromises or may compromise the confidentiality, integrity, availability, authenticity, or traceability of information or services.

Confidential information: nonpublic information whose unauthorized access or disclosure may harm TroqPay, customers, data subjects, partners, vendors, or third parties.

Competent partner: an institution or provider responsible for a financial, regulated, or critical step of an operation within its legal, regulatory, and contractual authority.

Third party: a vendor, service provider, partner, consultant, or person that processes information or accesses TroqPay assets.

4. Scope

This Policy applies to TroqPay officers, employees, contractors, vendors, and partners who have access to information, systems, services, or technology environments under the company's responsibility.

Where applicable, these guidelines also cover customers and platform users, particularly regarding credential protection, lawful use of services, and reporting of suspected incidents.

Contracts, Terms of Use, the Privacy Policy, internal standards, and partner rules may establish additional security obligations based on the nature and risk of the relationship.

5. Principles

  • Confidentiality: information is accessible only to authorized people and systems for legitimate purposes.
  • Integrity: information is protected against unauthorized alteration, destruction, or processing.
  • Availability: information and services are available to authorized people when needed, subject to contractual conditions and operational risks.
  • Authenticity: the identity of users, systems, and processes involved in accessing or processing information is verified.
  • Traceability: appropriate records support monitoring, investigations, audits, and accountability.
  • Least privilege: access is limited to what is necessary to perform authorized duties.
  • Prevention and proportionality: safeguards reflect asset criticality, data sensitivity, the state of technology, and identified risks.
  • Privacy and accountability: data is protected throughout the product lifecycle, and evidence is maintained in line with applicable obligations.

6. Governance and responsibilities

TroqPay Management is responsible for approving this Policy, supporting its implementation, and ensuring resources appropriate to the company's size, risks, and business model.

The functions responsible for security, technology, privacy, risk, and operations must coordinate to establish and review controls, assess risks, oversee material changes, coordinate incident response, promote awareness, and maintain records needed for accountability.

Employees, contractors, and third parties must comply with this Policy, use assets only for authorized purposes, protect credentials, and promptly report situations that may create security risk.

Each competent partner remains responsible for the controls, systems, regulatory obligations, and incidents related to the services it performs. TroqPay cooperates with those partners within the limits of its role, applicable law, and contracts.

7. Risk and information-asset management

TroqPay maintains a proportional process to identify relevant assets, assess threats and vulnerabilities, estimate impacts, and define security risk treatments.

Assets must have a designated owner and be protected throughout their lifecycle, from creation or procurement through disposal, termination, or replacement.

Information must be classified according to sensitivity, criticality, legal obligations, and potential impact. Classification guides access, use, sharing, storage, transmission, retention, and disposal.

Protection

Security controls

Public guidelines for identity, data, records, secure development, vulnerabilities, and recovery.

8. Protection guidelines

Access to information and systems must be individual, authorized, appropriate to the user's role, and governed by least privilege. Two-factor authentication is mandatory for administrative and internal access to systems and environments managed by TroqPay. The company maintains procedures for granting, reviewing, changing, and revoking access.

Credentials are personal and may not be shared. Passwords, keys, tokens, and other authentication mechanisms may only be shared through an expressly authorized corporate secret-management solution.

TroqPay applies encryption and data-protection measures in transit and at rest where appropriate to the nature of the information and technology context. Personal-data processing follows the LGPD, the Privacy Policy, data minimization principles, and applicable retention periods.

Access, event, and transaction records are retained to an extent consistent with security, fraud prevention, support, investigation, continuity, compliance, and legal-defense purposes.

Products, integrations, and technology changes must include security and privacy requirements from the planning stage, with risk-appropriate review, testing, dependency management, environment separation, secret protection, approvals, and rollback mechanisms.

TroqPay maintains a process to identify, assess, prioritize, and address vulnerabilities. Prioritization considers criticality, exploitability, potential impact, and asset exposure.

Relevant information and configurations are covered by a backup policy and recovery procedures appropriate to their criticality. The effectiveness of these mechanisms is assessed periodically.

9. Third parties, partners, and cloud computing

The engagement of third parties that may access, process, store, or transmit TroqPay information considers activity risk, data sensitivity, service relevance, and the third party's ability to meet security, privacy, continuity, and incident-reporting requirements.

Agreements with relevant third parties must address, as applicable, confidentiality, data protection, access control, incident reporting and cooperation, continuity, secure termination, subcontracting, international transfers, and the disposition of information when the relationship ends.

Use of cloud computing or third-party infrastructure does not transfer TroqPay's responsibilities for processing and controls within its role, nor does it transfer to TroqPay the regulatory responsibilities of competent partners.

Resilience

Incidents, continuity, and training

Guidelines for responding to security events, protecting data subjects, and maintaining relevant services.

10. Security incident management and response

TroqPay maintains internal procedures to receive reports and to identify, record, classify, contain, investigate, remediate, and track security incidents.

The response considers the nature of affected information and services, the extent of the impact, risks to data subjects, customers, and third parties, evidence preservation, and applicable legal, regulatory, and contractual obligations.

Depending on the circumstances, TroqPay may contain or temporarily limit access and functionality, preserve records, engage vendors or partners, recover services, remediate vulnerabilities, and strengthen controls.

Material incidents are reviewed to identify causes, impacts, corrective actions, and opportunities for improvement. Information is shared only with those who need it, within legal limits and without disclosure that could increase risk.

11. Personal-data incidents

Incidents involving personal data are assessed under the LGPD and regulations issued by Brazil's National Data Protection Authority (ANPD).

When TroqPay acts as controller and an incident may pose a relevant risk or harm to data subjects, the company will notify the ANPD and affected data subjects within the time and in the manner required by applicable law.

When TroqPay acts as processor, it will notify the responsible controller and provide the necessary cooperation. When an incident relates to a competent partner or third party, TroqPay will act within its role and cooperate with the party responsible for any required notifications.

Notifications will be clear and contain the information required by law without disclosing details that could compromise investigations, evidence, trade secrets, or the security of affected environments.

12. Continuity and resilience

TroqPay maintains continuity and recovery measures proportional to the criticality of its services and third-party dependencies.

Plans consider unavailability, technology failures, cyber incidents, vendor compromise, and other situations that may affect relevant activities. Procedures are reviewed and assessed periodically and following material changes or incidents.

Continuity of regulated financial steps also depends on the plans, systems, and decisions of the competent partners responsible for their execution.

13. Security awareness and training

TroqPay provides guidance and awareness activities appropriate to the roles and risks of officers, employees, and contractors.

Topics may include credential protection, social engineering, phishing, information handling, privacy, acceptable use, remote work, incident reporting, and responsibilities under this Policy.

Responsibilities

Responsibilities and reporting

Customer and user duties, the security channel, and consequences of violations.

14. Customer and user responsibilities

Customers and users must protect credentials, devices, keys, and integrations under their control; enable available security mechanisms; limit access to what is necessary; keep contact information current; use the platform lawfully and under the Terms of Use; and promptly report suspected fraud, account compromise, or credential exposure.

TroqPay may take protective and containment measures when it identifies material risk associated with credentials, integrations, devices, or platform use, subject to the Terms of Use and the responsibilities of competent partners.

15. Reporting vulnerabilities and security issues

Vulnerabilities, suspected incidents, or security issues involving TroqPay assets should be reported to security@troqpay.com.

Reports should provide enough information to identify and assess the issue without including personal data, credentials, secrets, or third-party information beyond what is strictly necessary.

Actions that cause service disruption, destruction, alteration, or exfiltration of data; persistent access; movement of funds; fraud; social engineering; privacy violations; or exploitation beyond what is necessary to demonstrate a potential vulnerability safely are not authorized.

TroqPay may request additional information and will take measures it considers appropriate based on risk. Submission of a report does not create an obligation to pay a reward, enter into a contract, or make a public disclosure.

The conditions for good-faith research, scope, unauthorized activities, and coordinated disclosure are detailed in TroqPay's Responsible Vulnerability Disclosure Policy.

16. Violations and enforcement measures

Violation of this Policy or related security standards may result, depending on severity and the legal relationship involved, in guidance, access restriction or revocation, disciplinary measures, contract suspension or termination, notice to partners or authorities, and appropriate legal or administrative action.

Measures will be proportionate, without limiting urgent action required to contain risk or preserve information, services, evidence, and rights.

Final provisions

Transparency, review, and effective date

Limits of public disclosure, Policy updates, and the record of the current version.

17. Confidentiality and transparency

This Policy presents the general framework of TroqPay's security governance. Publication does not disclose confidential information, trade secrets, or details that could compromise the security of the company, customers, partners, or third parties.

TroqPay may provide additional security information to customers, partners, auditors, or authorities based on legitimate need, risk assessment, and appropriate confidentiality obligations.

No system is completely immune to risk. This Policy does not guarantee uninterrupted availability or the complete elimination of incidents; it establishes guidelines for prevention, impact reduction, response, and continuous improvement.

18. Review, approval, and effective date

This Policy will be reviewed periodically and whenever there is a material change in TroqPay's business model, risks, services, applicable law, or obligations.

Version 1.0 was approved by TroqPay Management and is effective as of August 23, 2026. It remains in effect until replaced by a later version.

Material changes may be communicated through appropriate channels based on the nature of the change and applicable obligations.

Change log: Version 1.0, August 23, 2026, initial publication.