See the full list of cookies
Look up a CNPJ Talk to an expert Menu

Trust

Security, privacy and transparency in the use of data

Anyone who buys data to decide on credit, insurance and compliance needs to know where it comes from and how it is protected. Here are our answers, with what is in place and what we send on request.

Updated on .

Anatomy of a data pointIllustrative data
Entity
Exemplo Pecuária Ltda.
Finding
Environmental embargo notice on a linked rural property
Source
IbamaEmbargoed areas, public database
Collected
Methodology
score-v3.2
Evidence hash
sha256:9f2c…e41a
Illustrative example with a fictitious entity: each piece of information displayed keeps its source, collection date and methodology version.

In short

Controller of site data
ESGreen Avaliação e Monitoramento ESG Ltda., CNPJ 48.184.229/0001-50
Data protection officer (DPO)
dpo@esgreen.com.br
Hosting
Enterprise cloud, with details in the due diligence package
Administrative access to the site
Restricted to ESGreen corporate accounts
Optional cookies
Loaded only after your consent
Integrity channel
Whistleblower channel with an anonymity option
Vendor due diligence
Package sent on request

Information security

Controls described by scope: the corporate website and the ESGreen Platform.

Corporate website

Scope: esgreen.com.br

Hosting in Brazil.
The site, its content and files are hosted on an enterprise cloud in Brazil, with redundancy. Contact requests and Whistleblower channel reports are not stored on the site: they are forwarded by email to the responsible areas.
Encryption.
All traffic uses HTTPS, with TLS 1.2 or higher and HSTS. Stored data is encrypted at rest.
Administrative area.
Only ESGreen staff can sign in, with a corporate account and multi-factor authentication.
History and recovery.
Every content change creates a new version that can be restored.
Software delivery.
Deployment is automated and each version is tested before going to production.
Protected forms.
Submissions go through anti-bot verification, rate limiting and origin checks. The site does not store submissions or the sender's IP address: contact requests and reports are forwarded by email.

ESGreen Platform

Scope: dashboard and API

Cloud infrastructure.
The platform runs on an enterprise cloud. Region, backups and continuity are described in the due diligence package.
Data traceability.
Each piece of information displayed keeps its source, collection date and the methodology version used in the calculation.
Role-based access.
Each user has an access profile defined by the client and is linked to their company and, when needed, to their area or unit. In the Alert Center, each person sees only the alerts for the areas they work in.
Audit trail.
Actions on the platform are logged with user and date, and can be exported for audit.
Suppliers have no access to internal data.
In Supplier qualification and the Alert Center, the supplier responds through an individual, secure link and sees only what was requested of them.
Instances and communications with the client's brand.
The platform can run in an environment with the institution's own visual identity (white label), and emails to suppliers and monitored parties carry the client's brand.
Technical details on request.
Architecture, access controls, backups and continuity are described in the due diligence package.

Found a vulnerability?

If you have identified a possible security flaw on the site or the platform, write to contato@esgreen.com.br with the subject “Security”, a description and the steps to reproduce it. We ask that you do not access, alter or disclose third-party data and that you wait for our response before making the flaw public.

Privacy and LGPD

How we process personal data received through the site. The full text is in the Privacy Policy.

Controller
ESGreen Avaliação e Monitoramento ESG Ltda., CNPJ 48.184.229/0001-50, Av. Presidente Juscelino Kubitschek, 1327, 4º e 8º andares, Vila Nova Conceição, São Paulo/SP, CEP 04543-011
Data protection officer (DPO)
dpo@esgreen.com.br
Purposes and legal bases (summary; full text in the policy)
What we doLegal basis (LGPD)
Respond to a contact, demo or pre-assessment requestConsent (Art. 7, I)
Send content by email, when you askConsent (Art. 7, I)
Measure audience and site usageConsent (Art. 7, I), given in the cookie notice
Protect forms against abuse and keep the site secureLegitimate interest (Art. 7, IX)
Receive and investigate reports in the Whistleblower channelLegitimate interest (Art. 7, IX) and compliance with a legal obligation, where applicable (Art. 7, II)
Handle data subject requestsCompliance with a legal obligation (Art. 7, II)
Retention.
The site does not store contact requests or reports. Contact requests are forwarded by email to the sales team and kept for up to 24 months after the last contact; if the conversation leads to a contract, the periods set by the contract and legal obligations apply. Whistleblower channel reports go to the compliance area, with restricted access, and are kept for the duration of the investigation and for up to 5 years after the case is closed. The full retention periods are in the policy.
Processors.
Providers of hosting, email, contact management, anti-bot verification, audience analytics, video and accessibility. The full list, with each one's role, is in the policy.
Cookies.
No optional cookie is loaded before your consent. You can change your choice at any time under “Cookie preferences” in the footer.
Your rights.
Confirmation, access, correction, anonymization, blocking or deletion, portability, information on data sharing, and withdrawal of consent. Request them by email at dpo@esgreen.com.br.

Where the data comes from

The ESGreen Platform organizes information from public, regulatory and global databases. Each data point shows where it came from and when it was collected.

ESGreen integrates 70+ public, regulatory and global sources. They include databases from the Federal Revenue Service (Receita Federal), Ibama and ICMBio, INPE, the Rural Environmental Registry (SICAR) and the courts, national restrictive lists such as CEIS and CNEP, and international sanctions lists such as those of the UN, the European Union, the United Kingdom and OFAC.

Each piece of information is displayed with its source, collection date and methodology version. When the official source corrects a data point, the platform shows the corrected information from the next collection onward.

Some of these sources contain data on individuals, such as company partners and officers and politically exposed persons. ESGreen processes this data for the purposes contracted by clients, within the limits of the LGPD. The controller and processor roles in each contract are defined with the client.

Found incorrect data?

If any data about you or your company seems incorrect, write to dpo@esgreen.com.br if you are an individual, or to contato@esgreen.com.br if you are a company. Provide the CPF or CNPJ and the data you wish to dispute. We check the information at the source and reply with the outcome.

Correcting source data is the responsibility of the agency or database that published it. ESGreen reflects the updated official information.

Responsible use of artificial intelligence

We use AI where it reduces manual work and broadens the reading of risk. The result always shows the basis used, and the decision stays with the institution.

Where we use it

Climate forecasting in IRC-ESGreen.
AI forecasting models estimate rainfall, water deficit, frost, extreme temperature and wind by coordinate. Each run is dated and the calculation records the methodology version.
Document validation in Evidence Assessment.
AI checks whether the submitted document matches the evidence requested in the questionnaire.
Lawsuit reading in Pre-assessment.
AI categorizes the lawsuits associated with the CNPJ or CPF looked up.
News in monitoring.
AI groups news items by event and classifies them by risk. Each event goes through the ESGreen team before reaching the client.
Triage in the Alert Center.
AI organizes each alert and suggests the area that should handle it, following instructions the client itself defines.

Principles

Human review.
In Evidence Assessment, an ESGreen analyst reviews the AI's analysis and decides. News items only become alerts after review by the ESGreen team. In the Alert Center, the final sign-off always comes from a person on the client's team.
Explainable.
Every score and every index can be traced back to the sources and the model version used.
Versioned.
Methodology changes get a new version. Earlier results keep the version they were calculated with.
Input, not decision.
Results support decisions made by the institution itself, which sets limits, collateral and actions.
Illustrative data clearly labeled.
Public demos use synthetic data, always labeled “Illustrative data”.

Read the methodology

Methodology and model governance

A score only has value if it can be explained. We publish how we assess: the layers of the ESGreen Score, the formula and bands of IRC-ESGreen, the sources and the update criteria.

Read the methodology

Integrity

Whistleblower channel.
Anyone can report conduct contrary to ethics, the law or our policies, with an anonymity option and a reference number. Reports are forwarded by email to the area responsible for compliance, separate from the sales area, with no storage on the site. Access the channel
UN Global Compact.
ESGreen is a participant in the UN Global Compact.

Is your institution evaluating ESGreen as a vendor?

Institutions authorized to operate by the Central Bank assess providers of data processing, data storage and cloud computing services, as required by CMN Resolution 4,893/2021. We support this due diligence with technical documentation and answers to your questionnaire.

How it works

  1. You send the request through the form.

  2. An expert confirms the scope and, if needed, a non-disclosure agreement.

  3. We send the package to the designated contact.

Request due diligence package

Your request reaches ESGreen's sales and security team. We reply within one business day.

Frequently asked questions

Short answers to the most common questions.

Still have questions? Talk to an expert

Where is the ESGreen website hosted?

On an enterprise cloud in Brazil. Content and files are stored in the country. Contact requests are not stored on the site: they are forwarded by email to the sales team.

Where is the ESGreen Platform hosted?

The platform runs on an enterprise cloud. Details on region, backups and continuity are in the due diligence package, sent on request.

Does the site use cookies before I consent?

No. Before you choose, the site only uses what is necessary to work and to protect the forms. Analytics and marketing tools only load after you accept.

How do I exercise my rights under the LGPD?

Write to the data protection officer at dpo@esgreen.com.br. State what you want (access, correction, deletion or another right) and a way to contact you. We respond within the time limits set by the LGPD.

How does ESGreen process data on individuals found in public sources?

This data, such as that on company partners and officers, comes from official sources and is processed for the purposes contracted by clients, within the limits of the LGPD. Each data point shows its source and collection date. If anything about you is incorrect, write to dpo@esgreen.com.br.

How do I request the vendor due diligence package?

Through the contact form, with the subject "Information security and vendor due diligence". An expert confirms the scope and sends the package.

How do I report a security vulnerability?

Write to contato@esgreen.com.br with the subject "Security", a description and the steps to reproduce the issue. Do not access or disclose third-party data.

Shall we talk about the ESG and climate risks of your operation?

Book 30 minutes.

  • Demo with cases from your segment
  • Pre-assessment of CNPJs in your base
  • Climate exposure readout for operations and assets

Or write to contato@esgreen.com.br