Secure before it is built. Protected for as long as you run it.
You should not have to understand the jargon to know your systems are safe. This page says what Leapfrog does about security, in plain words, and what you get for as long as you are a client.
Before the first conversation, an NDA.
You will be asked to explain how your business really works, and that is not something to say to a stranger. So Leapfrog issues a mutual non-disclosure agreement for e-signing before the first conversation takes place. It covers what you tell us, what you show us and the fact that we spoke, whether or not any work follows. The full commitment is on the privacy page.
Security is the first thing planned, before any code
Every build starts with a written plan, and the first page of it is security: who can see what, how people sign in, where the data lives, and how it comes back if something goes wrong. You read that page before you accept the plan.
Built so it can be checked
These are the habits that keep a system secure after it is live. They cost nothing extra and they are part of every build.
Tested before it ships
Every change runs through an automated test suite before it can reach your system. A change that fails a test does not deploy, whatever the hour.
Every door checks who is knocking
Each request to the system is checked for who is asking and what they are allowed to do, on the server, every time.
The parts Leapfrog did not write are watched
Every system is built on third-party libraries. They are checked for known problems and kept current.
An annual security audit, for ongoing clients
For clients Leapfrog looks after on an ongoing basis, the software Leapfrog built for them is audited once a year as part of that relationship, not as a separate invoice. You get a written report in plain language: what was checked, what was found, and what was fixed.
- Who still has accessaccounts, roles, leavers Pending
- How people sign insecond factor on every account Pending
- Whether everything is currentsoftware and the libraries under it Pending
- Whether the backup comes backa restore, actually run Pending
- What is reachable from the internetand whether it should be Pending
- Where the data is and who sees itlocation, encryption, sharing Pending
The specimen above is illustrative. A real report names your systems, your dates and what changed since the last one. The audit covers what Leapfrog built and is part of an ongoing support relationship.
Insured, private, and yours
Insured
Leapfrog operates with business insurance in place. A certificate of currency is available on request before any work starts.
Private
Leapfrog is one person. There is no offshore team, no subcontractor and no shared login with access to your systems. The privacy page sets out what is held and for how long.
Yours
Every account, the code and the data are registered in your name. Leapfrog holds delegated access you can revoke in one action. The ownership page shows the structure.
Ask the questions you would ask anyone.
Where is my data? Who can see it? What happens if you disappear? Each has a short answer on this page and a longer one on the ownership page. The first conversation is free, and it starts with the NDA.