Skip to content

Trust & Security

Security isn'ta feature.It's the baseline.

How we protect our clients, how we build under audit, and how to reach us about a vulnerability.

How We Operate

The posture we hold ourselves to before anyone asks.

Encryption everywhere

Data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Keys and secrets live in managed vaults, never in source code, tickets, or chat.

Least-privilege access

People get access per project and per role, and we review that access on a fixed schedule. Everyone on the team signs in with SSO and hardware-backed multi-factor authentication.

A vetted team

Every Big Leap engineer and contractor passes a background check and signs confidentiality and security agreements before touching client work.

Accountable handling

Client data is classified and access is logged. Data is returned or destroyed when an engagement ends. We work from written policies, not good intentions.

How We Build

Practices your auditors will recognize.

(01)

Review on every change

No code reaches production without a peer review. In regulated engagements, we agree the review standard with your compliance team up front and produce the evidence after.

(02)

Scanning in the pipeline

Dependency, container, and static analysis scans run in CI on every change. Findings are ranked by severity and each severity has a set fix window.

(03)

A disciplined SDLC

Change management, separate environments, and release approvals come standard. These are the same gates your auditors expect to see when they review the systems we build.

(04)

Incident response

Defined escalation paths, client notification commitments, and a review after every incident. Security events get an owner and a deadline, like any other engineering problem.

Compliance Expertise

Software that passes the audit.

Big Leap is a consultancy, not a certified platform. The frameworks below describe the environments where our work passes review. They are not certifications we hold. That difference is exactly what keeps your auditors comfortable.

SOC 2 Type II

We design the controls, the evidence collection, and the systems behind them. We have taken client platforms from the first control to a clean Type II report.

HIPAA

We build systems that handle PHI under the required safeguards: access controls, audit trails, encryption, and BAAs where they apply.

21 CFR Part 11

We deliver validated software for life sciences teams: electronic signatures, immutable audit trails, and validation documents produced alongside the build.

FedRAMP & ATO processes

We build to the control baselines federal programs expect and support authority to operate packages. Big Leap does not hold a FedRAMP authorization. Our work passes these reviews inside our clients' environments.

Data Handling

What we hold, and how we treat it.

What this site collects

Contact and newsletter form submissions, plus first-party attribution analytics. Nothing more, and nothing sold. The details are in our privacy policy.

How engagement data is handled

Only the people assigned to your work can access your data. It lives in environments you approve, and it is returned or destroyed when the engagement ends.

Vendors & subprocessors

We use a small, reviewed set of vendors for cloud hosting, email delivery, and error monitoring. Each is bound by data processing terms. A current list is available on request.

Responsible disclosure

Found a vulnerability in this site or in something we've shipped? Report it to us directly. We acknowledge reports within two business days and credit researchers who follow coordinated disclosure. Please don't test against client systems or access data that isn't yours.

security@bigleap.app

Security Review

Put us through your review.

Vendor assessments, architecture reviews, penetration test coordination. We have sat on both sides of the questionnaire. Bring yours.

Take the Leap