Applies universally across all Leovoid-operated domains, Platforms, Products, Solutions, and Marketplace tools · Entity: Leovoid Technologies, Inc. (Delaware)
1. OUR APPROACH TO SECURITY
Security is treated as a continuing responsibility at Leovoid, not a one-time project. We invest on an ongoing basis in the infrastructure, personnel training, and technical safeguards described below, and we hold ourselves to a level of security consistent with the trust customers place in a platform that evaluates and helps remediate compliance issues on their own websites.
2. INFRASTRUCTURE AND HOSTING
The Site, Products, Solutions, and Marketplace tools are hosted on infrastructure operated by our hosting provider, currently located in the United States, as reflected on the Data Subprocessors page. Physical and environmental security of the underlying data center is maintained by that provider, consistent with the security measures described in the Data Processing Agreement’s Security Annex.
3. ENCRYPTION
Data is encrypted in transit using industry-standard transport encryption (such as TLS), and encrypted at rest where supported by the underlying storage infrastructure.
4. ACCESS CONTROLS AND AUTHENTICATION
Access to customer data is restricted to personnel and systems with a legitimate business need, governed by role-based permissions. Customer Accounts support multi-factor authentication, passkeys, and other authentication methods described in the Master Account Terms, and Leovoid personnel accessing a customer’s Account for support purposes do so only with session-based consent.
5. MONITORING AND THREAT DETECTION
We maintain network security controls and monitoring designed to detect and respond to unauthorized access attempts, and maintain a vulnerability management process for identifying and remediating security issues in our own systems within a risk-appropriate timeframe.
6. AVAILABILITY AND BUSINESS CONTINUITY
We target 99.9% monthly uptime for the Services, consistent with the Service Level Agreement available to Enterprise-tier customers, and maintain backup and disaster recovery practices designed to support continuity of service and protect against data loss.
7. INCIDENT RESPONSE
We maintain an incident response process designed to detect, investigate, and respond to a security incident, including the breach notification commitments described in the Data Processing Agreement.
8. COMPLIANCE AND CERTIFICATIONS
[PLACEHOLDER: to be updated as applicable — for example, SOC 2 Type II, ISO 27001, or other certifications, once obtained. Leovoid does not represent that it currently holds a certification not stated here.]
9. RESPONSIBLE DISCLOSURE
We welcome reports from security researchers, customers, and partners who identify a potential vulnerability, and are committed to working with anyone who responsibly and privately discloses a security concern before it is made public. To report a potential vulnerability, please contact us using the security contact information published in the Privacy Policy. We ask that reporters avoid accessing or modifying data that does not belong to them, avoid degrading the Services for other customers, and give us a reasonable opportunity to investigate and remediate a reported issue before public disclosure.
10. RELATIONSHIP TO OTHER DOCUMENTS
This Security Commitment is a general, public-facing description of our security practices and supplements, but does not replace or expand, the Data Processing Agreement’s Security Annex, which is the binding technical and organizational measures schedule incorporated into the Agreement, or the Service Level Agreement available to Enterprise-tier customers. In the event of any inconsistency, the Data Processing Agreement and the Service Level Agreement control.