Encryption everywhere
Data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Keys and secrets live in managed vaults, never in source code, tickets, or chat.
Trust & Security
How we protect our clients, how we build under audit, and how to reach us about a vulnerability.
How We Operate
The posture we hold ourselves to before anyone asks.
Data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Keys and secrets live in managed vaults, never in source code, tickets, or chat.
People get access per project and per role, and we review that access on a fixed schedule. Everyone on the team signs in with SSO and hardware-backed multi-factor authentication.
Every Big Leap engineer and contractor passes a background check and signs confidentiality and security agreements before touching client work.
Client data is classified and access is logged. Data is returned or destroyed when an engagement ends. We work from written policies, not good intentions.
How We Build
(01)
No code reaches production without a peer review. In regulated engagements, we agree the review standard with your compliance team up front and produce the evidence after.
(02)
Dependency, container, and static analysis scans run in CI on every change. Findings are ranked by severity and each severity has a set fix window.
(03)
Change management, separate environments, and release approvals come standard. These are the same gates your auditors expect to see when they review the systems we build.
(04)
Defined escalation paths, client notification commitments, and a review after every incident. Security events get an owner and a deadline, like any other engineering problem.
Compliance Expertise
Big Leap is a consultancy, not a certified platform. The frameworks below describe the environments where our work passes review. They are not certifications we hold. That difference is exactly what keeps your auditors comfortable.
We design the controls, the evidence collection, and the systems behind them. We have taken client platforms from the first control to a clean Type II report.
We build systems that handle PHI under the required safeguards: access controls, audit trails, encryption, and BAAs where they apply.
We deliver validated software for life sciences teams: electronic signatures, immutable audit trails, and validation documents produced alongside the build.
We build to the control baselines federal programs expect and support authority to operate packages. Big Leap does not hold a FedRAMP authorization. Our work passes these reviews inside our clients' environments.
Data Handling
Contact and newsletter form submissions, plus first-party attribution analytics. Nothing more, and nothing sold. The details are in our privacy policy.
Only the people assigned to your work can access your data. It lives in environments you approve, and it is returned or destroyed when the engagement ends.
We use a small, reviewed set of vendors for cloud hosting, email delivery, and error monitoring. Each is bound by data processing terms. A current list is available on request.
Found a vulnerability in this site or in something we've shipped? Report it to us directly. We acknowledge reports within two business days and credit researchers who follow coordinated disclosure. Please don't test against client systems or access data that isn't yours.
Security Review
Vendor assessments, architecture reviews, penetration test coordination. We have sat on both sides of the questionnaire. Bring yours.
Take the Leap