At Leasup, we take data integrity and security very seriously. Given the nature of the product and service we provide, it is important that we acknowledge our responsibilities as both a data controller and a data processor.
We store and process your data with care and help you stay compliant. For more information, see our Privacy Policy.
OVH's cloud infrastructure and services are certified ISO/IEC 27001, 27017, 27018 and 27701. These certifications ensure an information security management system (ISMS) is in place to manage risks and vulnerabilities and to ensure business continuity, as well as a privacy information management system (PIMS).
Data passing through Leasup is encrypted, both in transit and at rest. All browser connections to the Leasup platform are encrypted in transit using TLS SHA-256 with RSA encryption. Leasup requires HTTPS for all services.
Leasup databases are encrypted and automatically backed up every day. We use firewalls, strong user authentication, automatic session logout, and password salting and hashing.
All employees are trained in security and data handling to ensure they uphold our strict commitment to the privacy and security of your data.
All employees sign a confidentiality agreement before joining Leasup.
Leasup continuously monitors the product for service interruptions, performance degradation and security vulnerabilities, so that our engineers are alerted immediately and can take action as soon as an incident is detected.
New releases of the Leasup platform are carefully reviewed and tested to ensure high availability and an excellent customer experience. Changes to our codebase must include unit tests, integration tests and end-to-end tests. Changes run on our continuous integration server, allowing us to detect any development issue automatically.
We secure our employees' workstations and laptops to ensure every device meets our information security standards, including encryption.
Our employees' equipment is protected by anti-malware software, and we run routine phishing tests to further educate and train staff.
We keep our systems up to date with the latest security patches and continuously monitor new vulnerabilities through compliance and security mailing lists. This includes automated scanning of our code repositories for vulnerable dependencies.
We regularly carry out penetration tests (pentests) to detect vulnerabilities in our application and ensure its reliability.
The experts performing these tests are OSCP-certified and, more specifically, OSWE-certified.
Attack techniques tested:
XSS and DOM-XSS
All user input is properly encoded when displayed to ensure XSS vulnerabilities are mitigated.
CSRF
All POST requests are checked for a CSRF token before the request is processed.
SQL injection
We use prepared statements for database access to prevent SQL injection attacks.
Other
SSRF
BLIND SSRF
LFI/RFI
Directory Traversal
HTTP Smuggling
JSON exploitation
JavaScript exploitation
Session Hijacking
PHP Object Injection (serialisation)
Apache 0-day
Information Disclosure
The General Data Protection Regulation (GDPR) is a European privacy law that came into force on 25 May 2018. The GDPR replaces the EU Data Protection Directive, also known as Directive 95/46/EC, and aims to harmonise data protection laws across the European Union (EU) by applying a single data protection law that is binding in every Member State.
Our GDPR commitment
Protecting our customers' personal data is at the heart of Leasup's internal operations. We only collect and store the information needed to deliver our service, and we do so with our customers' consent. Our approach to privacy, security and data protection is also aligned with the objectives of the GDPR.
For more information, see our Privacy Policy.