Information Security & Data Protection
Since 2012, we've been helping organizations protect their data, systems, and people with specialized services in offensive security, compliance, and awareness.
What we do
Complete assessment of your organization's security posture, identifying vulnerabilities and risks.
Learn moreCompliance with data protection regulations, from diagnosis to full implementation.
Learn moreIn-depth penetration testing for businesses. Web, API, Infrastructure and Mobile Pentesting following OWASP, NIST and PCI DSS. Reports within 20 days.
Learn moreContinuous penetration testing with defined cadence, predictable per-cycle cost and auditable CWSS prioritization.
Learn morePenetration testing on networks, servers, and Active Directory. From automated scanning to full pentesting with manual exploitation.
Learn morePhishing simulations to test and train employees against social engineering.
Learn moreRisk assessment and compliance for Artificial Intelligence projects.
Learn moreTeam training in information security, data protection, and awareness.
Learn moreDevelopment of information security policies, standards, and procedures.
Learn moreWhere we operate
We serve companies across various industries, adapting our security solutions to the specific needs of each market.
Banks, fintechs, credit unions, and financial institutions.
Software companies, SaaS, startups, and IT service providers.
Hospitals, clinics, laboratories, and health insurance providers.
Universities, schools, edtechs, and educational institutions.
E-commerce, retail chains, and consumer goods companies.
Companies that trust BrownPipe
What they say
Podcast
For over 10 years, the Segurança Legal podcast has covered the most relevant topics in Information Security, Data Protection, and Technology Law. Produced by BrownPipe's founding partners, the show has over 400 episodes.
Shownotes STF ajusta tese sobre responsabilidade de redes sociais Segurança Legal – #395 – A inconstitucionalidade do art. 19 do MCI ConJur, “Decretos das plataformas digitais: o que muda, o que avança e o que ainda preocupa” Após alerta do ChatGPT, FBI avisou polícia brasileira sobre plano de pai matar filho para não pagar pensão no ES The Hacker News — Fake AI Agent Skill Passed Security Scans The Next Web — Fake AI agent skill bypassed every scanner Cybernews — Researchers hijack 26,000 AI agents The Register — Mythos discovers ‘Squidbleed’ The Hacker News — 29-Year-Old Squid Proxy Bug ‘Squidbleed’ Cyber Press — Squidbleed discovered with Claude Mythos Preview Imagem do Episódio – Composição VII – Kandinsky
Listen to episode
Neste episódio falamos sobre o recente ataque ao sistema de alertas da defesa civil. Visite nossa campanha de financiamento coletivo e nos apoie! Conheça o Blog da BrownPipe Consultoria e se inscreva no nosso mailing ShowNotes Ataque ao Defesa Civil Alerta expõe fragilidade digital que TCU denuncia desde 2024 Humanos, chegamos”: invasão ao Cell Broadcast expõe falha inaceitável em infraestrutura Polícia Federal investiga alerta falso em sistema da Defesa Civil que acordou milhões de brasileiros Ataques hackers causam pesadelo à segurança da informação do governo Brazil probes emergency warning system after nationwide rogue alert Imagem do episódio – A Grande Onda de Kanagawa de Katsushika Hokusai
Listen to episode
Neste episódio falamos sobre o bloqueio do modelo Fable pelo governo americano. Visite nossa campanha de financiamento coletivo e nos apoie! Conheça o Blog da BrownPipe Consultoria e se inscreva no nosso mailing ShowNotes Amazon denunciou Anthropic. Empresas de segurança cibernética reagem e alertam para perigo da decisão Anthropic’s Claude Fable 5 Alleged Jailbreak to Generate Stack Exploits Statement on the US government directive to suspend access to Fable 5 and Mythos 5 Trump’s new AI executive order drastically shifts the administration’s stance on the tech Trump signs AI executive order asking companies to give government early access to models New AI Executive Order Calls for Frontier Model Security, Early Government Access and AI-Enabled Cyber Defense Trump Wants Frontier AI Models 30 Days Before Launch. The Order Can’t Force It. Anthropic CEO warns that without guardrails, AI could be on dangerous path Artigo – Biased AI writing assistants shift users’ attitudes on societal issues Vídeo – Anthropic CEO warns that without guardrails, AI could be on dangerous path Vídeo – Has the US government called Anthropic’s bluff? | DW News Vídeo – Hegseth: “Anthropic is run by an ideological lunatic.” Imagem do Episódio: “Prometheus Bound” por Peter Paul Rubens.
Listen to episodeBrownPipe Space
The BrownPipe Space is an environment created within Setrem College, in Três de Maio/RS, to bring together industry and academia.
More than a physical space, it represents our commitment to sharing knowledge and fostering innovation, connecting information security, data protection, and artificial intelligence to the training of future professionals.
With this initiative, we reinforce our mission to support education, the community, and the building of a safer digital culture.
Content
Articles and news about information security, data protection, and technology.
The attack on Brazil's Civil Defense alert system exposed basic access control and authentication failures. We analyze what was missing and why.
Read moreDecree 12,975/2026 regulates the Marco Civil after the STF ruling and creates new duties for log retention (logical ports) and content moderation. Understand the impacts.
Read moreA firewall won't stop a deceived employee. Understand why human behavior has become the main battlefield in cybersecurity and what your company can do before the next attack happens.
Read moreGet in touch