Transparency

Summary of Revolut Brazil's Information Security Policy

This is a summary of Revolut Brazil's group Infosec Policy.

1. Introduction

Revolut Brasil has a responsibility to ensure that the information, information systems and intellectual property entrusted to it by its customers, partners and employees are properly protected and used for business purposes and in line with its risk appetite and to support the organisation's objectives.


It is therefore important that information security objectives are clearly defined and take into account the business strategy, applicable regulations and legislation and the information security threat environment.


This summary has been prepared to enable visibility of these objectives, the principles and controls adopted at organisational, people, physical and technological levels.


Revolut's information security policies are reviewed annually or whenever necessary.

(a) Scope

This document highlights the main issues related to Information Security and Cybersecurity regarding the Information Security Policy of Revolut Sociedade de Crédito Direto S.A and Revolut Tecnologia Brasil Ltda. (jointly defined as "Revolut Brazil").


The rules apply to all Revolut Brazil group entities (current and future), as well as to all its employees, including service providers or outsourced employees.

(b) Goals and Principles

The goals of the security of information owned and/or held by Revolut Brazil are:

  • Preventing, detecting and resolving incidents related to the cyber environment and information leaks in physical space;
  • Reduce and mitigate risks and vulnerabilities, establish measures to protect sensitive and confidential information and maintain business continuity; and
  • Use practices and technologies aimed at preserving the following information security principles:
  1. Confidentiality;
  2. Integrity;
  3. Availability; and
  4. Authenticity.

2. Procedures and Controls in Place

The categories of procedures and controls adopted by Revolut Brazil, which ensure a consistent and effective approach to the management of information and related incidents, and which are in line with best practices and security frameworks are:

  • Access control and authentication;
  • Cryptography;
  • Intrusion and leak prevention and detection;
  • Periodic vulnerability tests and scans;
  • Protection against malicious software;
  • Tracing mechanism;
  • Segregation of computer networks;
  • Backups;
  • Secure development;
  • Incident management and scenarios to be considered in business continuity tests and plans; and
  • Third-party management.

3. Raising Awareness

Revolut Brazil recognises the importance of raising awareness among its employees, contractors and customers about cybersecurity risks and best practices. For this reason, Revolut Brazil will adopt mechanisms to disseminate the cybersecurity culture within the organisation in accordance with the information security awareness and acceptable use policy. This includes periodic training and awareness programmes for all employees to ensure that they are aware of and comply with the information security policy and other relevant policies and procedures.


Revolut offers tips on how to avoid and combat fraud and scams here, and it also addresses possible cybersecurity threats, as well as the procedures that customers can adopt to prevent them. Revolut also has a responsible disclosure programme where users can report information or suspected vulnerabilities in any of our services. More details here.