Security & trust

Secure before it is built. Protected for as long as you run it.

You should not have to understand the jargon to know your systems are safe. This page says what Leapfrog does about security, in plain words, and what you get for as long as you are a client.

Before the first conversation, an NDA.

You will be asked to explain how your business really works, and that is not something to say to a stranger. So Leapfrog issues a mutual non-disclosure agreement for e-signing before the first conversation takes place. It covers what you tell us, what you show us and the fact that we spoke, whether or not any work follows. The full commitment is on the privacy page.

Security is the first thing planned, before any code

Every build starts with a written plan, and the first page of it is security: who can see what, how people sign in, where the data lives, and how it comes back if something goes wrong. You read that page before you accept the plan.

YOUR DATA

Who can see what. Written into the plan before the build starts, and checked again at every audit.

Built so it can be checked

These are the habits that keep a system secure after it is live. They cost nothing extra and they are part of every build.

Tested before it ships

Every change runs through an automated test suite before it can reach your system. A change that fails a test does not deploy, whatever the hour.

Every door checks who is knocking

Each request to the system is checked for who is asking and what they are allowed to do, on the server, every time.

The parts Leapfrog did not write are watched

Every system is built on third-party libraries. They are checked for known problems and kept current.

An annual security audit, for ongoing clients

For clients Leapfrog looks after on an ongoing basis, the software Leapfrog built for them is audited once a year as part of that relationship, not as a separate invoice. You get a written report in plain language: what was checked, what was found, and what was fixed.

  • Who still has accessaccounts, roles, leavers Pending
  • How people sign insecond factor on every account Pending
  • Whether everything is currentsoftware and the libraries under it Pending
  • Whether the backup comes backa restore, actually run Pending
  • What is reachable from the internetand whether it should be Pending
  • Where the data is and who sees itlocation, encryption, sharing Pending

Six checks, once a year, on the software Leapfrog built for its ongoing clients. The report comes to you in plain words, with the fixes already made.

The specimen above is illustrative. A real report names your systems, your dates and what changed since the last one. The audit covers what Leapfrog built and is part of an ongoing support relationship.

Insured, private, and yours

Insured

Leapfrog operates with business insurance in place. A certificate of currency is available on request before any work starts.

Private

Leapfrog is one person. There is no offshore team, no subcontractor and no shared login with access to your systems. The privacy page sets out what is held and for how long.

Yours

Every account, the code and the data are registered in your name. Leapfrog holds delegated access you can revoke in one action. The ownership page shows the structure.

Next step

Ask the questions you would ask anyone.

Where is my data? Who can see it? What happens if you disappear? Each has a short answer on this page and a longer one on the ownership page. The first conversation is free, and it starts with the NDA.

Perth & Western Australia · On-site discovery preferred · Remote available