X

Information Security Policy - External

At Zallpy Software LTDA, information security is treated as a strategic pillar for sustaining business operations, protecting information assets, ensuring data privacy, and preserving the trust of customers, suppliers, partners, and other interested parties.

Our commitment to security goes beyond technological protection: it involves processes, governance, people, and continuous controls aimed at ensuring the protection of information throughout its entire lifecycle.

This public policy presents, in a summarized manner, the main commitments and practices adopted by Zallpy to ensure the adequate protection of the information under its responsibility.

1. Our Commitment to Information Security

Zallpy adopts structured practices to protect corporate information, client data, technological assets, and information shared by third parties.

Our commitment is based on five essential pillars:

Confidentiality: We ensure that information is accessed exclusively by authorized individuals, according to their business need and permission level.

Integrity: We adopt mechanisms to ensure that information remains accurate, complete, and protected against improper or unauthorized alterations.

Availability: We maintain controls to ensure that information, systems, and services are available whenever necessary to support operations and commitments with clients.

Authenticity: We ensure identity, origin, and legitimacy validation mechanisms for information and transactions performed within our environments.

Traceability: We maintain records and audit trails that allow monitoring, investigation, and accountability of actions performed in our systems.

2. Governance and Security Management

Information security at Zallpy is structured through a formal governance model, with a clear definition of responsibilities, risk management processes, and security controls.

Our model includes:

• definition of internal policies and standards;

• continuous risk management;

• periodic audits;

• monitoring of environments and assets;

• continuous review and improvement of implemented controls.

Additionally, Zallpy adopts the principles of least privilege, need-to-know, segregation of duties, risk-based management, and information protection throughout its entire lifecycle, from creation to secure disposal.

This model enables constant evolution in response to technological, regulatory, and cyber threat changes.

3. Data Protection and Privacy

The protection of personal data and sensitive information is treated with a high level of priority.

Zallpy adopts practices to ensure that data is processed based on the principles of:

• purpose limitation;

• necessity;

• adequacy;

• data minimization;

• adequate retention;

• secure disposal.

Additionally, we implement technical and administrative controls to prevent unauthorized access, data leakage, or improper use of information.

4. Access Control

Access to corporate information and systems is controlled based on the principle of least privilege, ensuring that each user has only the accesses strictly necessary to perform their activities.

Our controls include:

• individual authentication;

• access segregation;

• periodic permission reviews;

• immediate revocation in cases of termination or role change;

• multi-factor authentication, when applicable.

These controls reduce the risks of unauthorized access and data exposure.

5. Technological Security

Zallpy’s technological infrastructure is protected by security mechanisms aimed at the prevention, detection, and response to threats.

Among the adopted controls are:

• endpoint protection;

• event monitoring;

• vulnerability management;

• patch and update management;

• encryption;

• network protection;

• data backup and recovery.

These mechanisms contribute to reducing the attack surface and increasing operational resilience.

6. Security Incident Management

Zallpy maintains formal processes for the identification, registration, analysis, containment, and handling of information security incidents.

When an incident is identified, proportional measures are adopted to:

• contain the impact;

• preserve evidence;

• restore operations;

• evaluate root cause;

• implement preventive improvements.

Our objective is to ensure a fast, efficient, and structured response.

7. Business Continuity

We maintain operational continuity mechanisms to minimize impacts resulting from failures, unavailability, or incidents that may affect our services.

This includes:

• backup routines;

• recovery tests;

• contingency processes;

• operational recovery measures.

8. Security in the Supplier Chain

Information security is also considered in our relationship with suppliers, partners, and third parties.

Third parties that have access to Zallpy’s data, systems, or environments must comply with minimum security, confidentiality, and information protection requirements.

Whenever necessary, we conduct risk assessments and compliance validations.

9. Awareness and Security Culture

We believe that information security depends on technology, processes, and human behavior.

Therefore, we promote continuous awareness and internal training initiatives to strengthen the culture of information protection, security best practices, and incident prevention.

Strong security is not born from a firewall. It is born from culture. The firewall only prevents the problem from entering; culture prevents it from being invited.

10. Compliance and Continuous Improvement

Zallpy maintains a permanent commitment to the continuous improvement of its Information Security Management System, promoting the evolution of security processes, controls, and practices, as well as compliance with legal, regulatory, contractual, privacy, and customer requirements.

Our security environment is continuously monitored and reviewed to respond to evolving threats, technological changes, and business needs.

11. Contact Channel

Requests related to Information Security, privacy, compliance, or security requirements from suppliers and clients may be forwarded through our official communication channels.

Zallpy maintains a formal channel for the evaluation of security requirements, supplier due diligence, and matters related to information protection.

12. Effective Date

Effective date: June 22, 2026, rev.: 04.

Offices

DALLAS - TX

Star District - 5 Cowboys Way, Ste. 300 - 71, Frisco, Texas

PHONE

+1 (469) 642-9366

SÃO PAULO – SP

Alameda Vicente Pinzon, 54 – Cubo Itaú

PORTO ALEGRE - RS

Av. Farrapos, 3857 - Floresta - 4º Distrito

FLORIANÓPOLIS - SC

SC 401, Km 4 - ACATE