Information Security

Information Security

Information is one of the most valuable assets of this century. The bank/client partnership involves ongoing and multiple interactions, which is why we work hard on ensuring the confidentiality, integrity and availability of data.

Information Security is defined as a set of controls, including policy, standards, processes, organizational structures and security procedures designed to protect information.

In addition to a password, we use a second authentication factor to validate transactions in electronic channels. We use the concept of digital validation with the second factor in Web and Mobile transactions. This raises the level of security through an optical reading of the physical token and the QR-Code technology integrated into the Bradesco Celular application. These security controls provide clients with greater autonomy, better experience and it is more convenient to perform transactions on digital channels, like unlocking a card, personalizing transaction limits, or making payments and transfers – without the need to visit a branch. Please note that, to validate access and transactions in other service channels, the password and security devices (physical token and MToken) must be used.

Handprint biometrics, used in our self-service machines, reinforces the security and convenience of account holders, non-account holders and attorneys. This form of biometric authentication was chosen by Bradesco because it is one of the most secure verification methods on the market. Corporate facial biometrics authenticate, identify and/or confirm a person’s identity using their face. In its first use case, biometrics is available as an additional authentication factor for mobile token sign up via the app. We also offer voice biometrics, available for use on the Fone Fácil channel.

Additionally, clients using the Internet Banking channel (Individuals) and Net Empresa Portal (Companies) can access the Bradesco security component (on desktops and notebooks), which is designed to provide more security when performing online transactions.

It is also possible to register the password to access digital channels (4-digit password) directly in the Bradesco Mobile App. This feature is available to individuals, first account holders, Physical Token users, or Mobile Token clients. And for those clients looking for increased security and convenience, we offer its Bradesco exclusive browser for desktops and laptops, which provides more ease when it comes to browsing through digital channels.

In a never-ending quest to anticipate the mitigation of risks in its activities, Bradesco monitors its data and transaction environments continuously (24/7), employing technology, processes and personnel specialized in the field.

The products and services are analyzed by a team of experts, who are focused on continuously working on the prevention and correction of actions to ensure the security of the information, in systems that provide support to the business and are aligned with the clients’ usability.

In April 2023, the Organization achieved SOC 2 Type II Compliance, rendered through a specialized independent audit. This Assurance confirmed the consistency and effectiveness of the controls that have been put in place for the security of the IT environment related to the financial services provided. The assessment is based on international standard information security criteria and controls for SOC 2 (AICPA – Association of International Certified Professional Accountants) covering the categories of services: security, availability, processing integrity, confidentiality and privacy.

We have also adopted the concepts of Privacy by Design / by Default in order to ensure that privacy and data protection are considered from the start of projects. The appointed Data Protection Officer (DPO) is responsible for privacy and data protection, as well as for observing the laws and regulations on the issue, particularly Law 13,709/2018 (Brazilian General Data Protection Regulation, LGPD in Portuguese), with a dedicated team that is integrated with Corporate Security. Support for data subjects, clients and the general public is facilitated by self-service tools in our digital channels and through service channels like the Customer Service Center (SAC), bank branches and the electronic form available at the link (Portuguese only): Bradesco Segurança | Lei Geral de Proteção de Dados | Fale com o DPO (bradescoseguranca).

In addition, we keep educational content on social media and institutional site (bradescoseguranca and bradescofornecedores) about digital security and data protection. We also have a channel where the public can forward suspicious messages, the evidencia@bradesco.com.br, aiming to combat malicious actions.