Trust
Security atLogicLeap.
How we look after the security of the websites, apps and platforms we build and run.
1.Who is responsible
Josh Matthews, Founder and Director of LogicLeap Ltd, leads security at LogicLeap. He is accountable for the security of everything we build and operate, including the platforms we run for clients under contract, and he handles every vulnerability report personally.
2.What it covers
This applies to LogicLeap's own websites and products, and to the client websites, web apps and mobile apps that we build, host and maintain. Some of these handle sensitive personal and payment data, so security is part of how we build and look after them, not an add-on.
3.How we work
- Code is reviewed for security issues before it reaches production, including access control, authentication and payment paths.
- Dependencies are audited and patched as part of ongoing maintenance.
- Production errors, uptime and broken assets are monitored around the clock, with alerts going straight to the person responsible.
- Access to systems and data is limited to what each person or service needs, and credentials are kept out of source code.
- Sites are served over HTTPS, and payments are handled by established providers such as Stripe, so card details never touch our servers.
4.Reporting a vulnerability
If you think you have found a security issue in anything we build or run, please email support@logicleapit.co.uk with “Security report” in the subject. Include what you found, where, and the steps to reproduce it.
We will acknowledge your report, keep you updated while we fix it, and credit you if you would like. Please give us reasonable time to fix the issue before sharing it, and do not access, change or delete data that is not yours while testing.