1. Why this page is written the way it is
Your customer list, your job history and your payment records are among the most sensitive assets your business owns. You are entitled to know how they are handled.
Service Leopard is a platform under active development, and this page describes what it is being built to do. We do not claim any certification we do not hold. We hold no SOC 2, ISO 27001 or PCI DSS attestation today. If and when we complete a formal audit, we will say so here, name the auditor and the scope, and make the report available under NDA. Until then, nothing on this page should be read as a certification.
2. Data protection in transit and at rest
- All traffic between your browser and the platform is encrypted in transit using current TLS.
- Data is encrypted at rest by the underlying storage and database services we build on.
- Backups are encrypted and are held under the same access controls as production data.
3. Access control
- The platform is being built around role-based access, so a business owner can decide what each member of their team can see and do.
- Internal administrative access is limited to the people who need it to operate and support the service, on a least-privilege basis.
- Administrative access requires multi-factor authentication, and access is reviewed when roles change.
- Credentials and secrets are held in managed secret storage, never in source code.
4. Payments
We do not store full card numbers. Card data is collected and processed by our third-party payments partner, which maintains its own PCI DSS compliance for that processing. Service Leopard receives only the limited transaction and payout status information it needs to show you what happened. See section 4 of the Terms of Service for our role as a platform.
5. Infrastructure and resilience
- The platform runs on established cloud infrastructure providers rather than self-administered hardware.
- Environments are separated, so development and testing never run against live customer data.
- Backups are taken on a regular schedule and restoration is tested, so that recovery is a practised procedure rather than a theory.
- Dependencies are monitored for known vulnerabilities and patched on a defined cadence.
6. How we build
- Changes are reviewed before they reach production.
- Access to production systems is logged, so administrative activity can be reconstructed.
- Security is considered when features are designed, not bolted on after they ship.
7. Incident response
We maintain a defined process for identifying, containing and investigating security incidents. If an incident affects your data, we will notify you without undue delay, tell you what we know and what we do not yet know, describe what we are doing about it, and follow up with the outcome. We will meet the notification obligations that apply to us by law.
8. What we need from you
Security is shared. Please use a strong, unique password, enable multi-factor authentication where it is offered, give each team member their own login rather than sharing one, remove access promptly when someone leaves, and tell us straight away at [SUPPORT EMAIL — e.g. support@serviceleopard.com] if you think an account has been compromised.
9. Reporting a vulnerability
If you believe you have found a security vulnerability, we want to hear from you. Email [LEGAL / PRIVACY EMAIL] with the subject line “Security Report” and enough detail for us to reproduce the issue.
We ask that you give us a reasonable opportunity to fix the issue before disclosing it publicly, that you do not access, modify or delete data belonging to anyone else, and that you do not degrade the service for other users while testing. If you act in good faith and within those limits, we will not pursue action against you for your research, and we will credit you if you would like us to.
[PLACEHOLDER: IF YOU LATER RUN A BUG BOUNTY OR FORMAL DISCLOSURE PROGRAMME, ADD ITS SCOPE, REWARDS AND SAFE-HARBOUR TERMS HERE.]
10. Contact
Valoria Ventures LLC dba Service Leopard
[BUSINESS MAILING ADDRESS — use registered agent or virtual office address, NOT a home address]
[LEGAL / PRIVACY EMAIL]