LekkerApps is committed to protecting your data with industry-standard security practices. This whitepaper outlines our technical security measures, compliance certifications, and security roadmap.
Data Encryption
All data is encrypted at rest using AES-256 encryption. Data in transit is protected by TLS 1.2+ for all connections between clients, servers, and third-party services. Database backups are encrypted and stored in geographically separate locations. API keys and sensitive credentials are stored in encrypted vaults, never in source code.
Access Controls
LekkerApps implements role-based access control (RBAC) with workspace-level permissions. Row-level security (RLS) policies ensure users can only access data within their workspace. Administrative actions are logged in audit trails. Multi-factor authentication is available for all accounts. Session management includes configurable timeouts and token rotation.
Infrastructure Security
Our platform runs on enterprise-grade cloud infrastructure with automatic scaling, redundancy, and disaster recovery. Database services include automatic backups with point-in-time recovery. Network security includes firewalls, DDoS protection, and private networking between services. Edge functions execute in isolated environments with minimal permissions.
Application Security
We follow secure development practices including code review, dependency scanning, and automated security testing. Input validation and parameterized queries prevent injection attacks. Content Security Policy headers prevent cross-site scripting. Rate limiting protects against abuse and brute-force attacks.
Compliance Status
LekkerApps is designed for compliance with POPIA (Protection of Personal Information Act, South Africa) and GDPR (General Data Protection Regulation, EU). We provide Data Processing Agreements, sub-processor transparency, and data subject rights tools. SOC2 Type II and ISO 27001 certifications are on our roadmap for enterprise customers.
Incident Response
We maintain an incident response plan with defined procedures for detection, containment, eradication, and recovery. Data breach notifications are sent within 72 hours as required by POPIA and GDPR. Post-incident reviews drive continuous improvement of our security posture.
Security Contact
To report a security vulnerability or concern, contact us at softwazapps@gmail.com. We take all security reports seriously and will respond within 24 hours.