Mariana Bittencourt
Founder · CEOFifteen years in financial-sector security, formerly leading the response team at a national payments company.
About the studio
NavegaFluxo began in 2017 with a simple frustration: most companies only thought about security after something had already gone wrong. We built a different model — a team that pays attention before the call, not after.
How we started
Our founders spent years on the receiving end of breach calls inside Brazilian banks and retailers. The pattern was always the same: the warning signs had been there for weeks, sitting in logs nobody read.
So we built a service around reading them. Not a dashboard you log into and forget, but a staffed center where a person notices the odd login at 2 a.m. and decides whether it matters.
Today we run that center from Itaim Bibi in São Paulo, covering companies in logistics, healthcare, finance, and retail. The work is unglamorous on purpose. A good month is one where nothing happens — because we caught it earlier.
What we believe
A clear explanation of a real risk is worth more than a thousand alerts nobody understands.
Principles
We explain risk the way you would explain it to your own board — in sentences, not severity scores. If you cannot act on what we tell you, we have not finished the job.
We do not sell fear or stack tools you will never use. We recommend the smallest change that closes the real gap, and we say when something is good enough.
Automation triages; people decide. Every confirmed incident reaches a named analyst who owns it through to the written summary.
We handle telemetry under the LGPD, keep it in Brazil where we can, and tell you exactly what we collect and why before we connect anything.
By the numbers
The people in charge
A small team that has run security operations through real incidents, not just tabletop exercises.
Fifteen years in financial-sector security, formerly leading the response team at a national payments company.
Runs the monitoring center and on-call rotation. Builds the detection rules our analysts work from.
Specialises in cloud workload defense and the slow, patient work of threat hunting across large estates.
Translates technical findings into LGPD reporting and the audit trails regulated clients need to keep.
Tell us what you run and where you worry. We'll come back with an honest read of where to start.