Public assurance / Current status

Compliance & Security

This page describes LeapView's current security and assurance posture using evidence-backed status categories. It is a transparency resource, not a certification, audit opinion, or statement of universal regulatory compliance.

01 / Assurance state

Current assurance state

Technical controls and qualification work are progressing. Final service scope, provider, legal and privacy approvals, operational commitments, and management approval remain separate decisions.

Managed-service launch

Pending approval

02 / In the product

Implemented capabilities

These describe repository-level product behavior. They do not establish that a managed deployment has been qualified or approved.

Implemented

Application access

LeapView implements authenticated application surfaces and role-, grant-, and policy-based permission checks for supported operations.

Read access documentation

Implemented

Audit capture

LeapView records selected administrative and security events, and governed query events, with project and actor context.

Read audit documentation

Implemented

Credential revocation

LeapView implements controls to revoke principal sessions, API tokens, and service-principal secrets.

Read token documentation

03 / Bounded exercises

Qualification-tested capabilities

A test result applies to its tested scenario, not automatically to an operating customer service.

Qualification-tested

Coordinated recovery handoff

Qualification testing has exercised coordinated PostgreSQL and object-storage restore handoff and a separate downstream consumer after the producing process exits, using bounded test resources. This does not establish a production provider, replacement-host activation, or a recovery-time commitment.

04 / Remaining work

Pending verification & approval

The following are open qualification or decision areas; their presence here is not a delivery promise or deadline.

Pending approval

Service scope & providers

Managed provider, region, service boundary, and contractual scope.

Pending verification

Managed identity

Managed-service identity, MFA, and privilege enforcement.

Pending verification

Privacy lifecycle

Retention, customer-rights operation, customer exit, and deletion across the proposed service.

Pending verification

Managed configuration

Target configuration, egress, and isolation on the proposed deployment.

Pending verification

Operations & assurance

Incident and support operation, independent penetration testing, and workforce and supplier assurance.

Pending approval

Final review

Legal, privacy, security, and management launch decisions.

05 / Claims boundary

Certifications & regulatory status

Standards and laws require scope-specific assessment. This page is not that assessment.

Not currently claimed

  • ISO/IEC 27001 certification is not currently claimed.
  • No universal GDPR compliance claim is made.
  • No universal NIS2, DORA, or CRA compliance claim is made.
  • No CIS certification or compliance claim is made.

Conditional regulatory applicability is determined separately and is not established by this page.

06 / Further information

Documentation & security reporting

Explore the public documentation and source repository. Please report a suspected vulnerability privately.

Last reviewed: . Public statements are reviewed and updated when the underlying evidence, service scope, or approval state changes.