Public assurance / Current status
Compliance & Security
This page describes LeapView's current security and assurance posture using evidence-backed status categories. It is a transparency resource, not a certification, audit opinion, or statement of universal regulatory compliance.
01 / Assurance state
Current assurance state
Technical controls and qualification work are progressing. Final service scope, provider, legal and privacy approvals, operational commitments, and management approval remain separate decisions.
Managed-service launch
Pending approval02 / In the product
Implemented capabilities
These describe repository-level product behavior. They do not establish that a managed deployment has been qualified or approved.
Implemented
Application access
LeapView implements authenticated application surfaces and role-, grant-, and policy-based permission checks for supported operations.
Read access documentationImplemented
Audit capture
LeapView records selected administrative and security events, and governed query events, with project and actor context.
Read audit documentationImplemented
Credential revocation
LeapView implements controls to revoke principal sessions, API tokens, and service-principal secrets.
Read token documentation03 / Bounded exercises
Qualification-tested capabilities
A test result applies to its tested scenario, not automatically to an operating customer service.
Qualification-tested
Coordinated recovery handoff
Qualification testing has exercised coordinated PostgreSQL and object-storage restore handoff and a separate downstream consumer after the producing process exits, using bounded test resources. This does not establish a production provider, replacement-host activation, or a recovery-time commitment.
04 / Remaining work
Pending verification & approval
The following are open qualification or decision areas; their presence here is not a delivery promise or deadline.
Pending approval
Service scope & providers
Managed provider, region, service boundary, and contractual scope.
Pending verification
Managed identity
Managed-service identity, MFA, and privilege enforcement.
Pending verification
Privacy lifecycle
Retention, customer-rights operation, customer exit, and deletion across the proposed service.
Pending verification
Managed configuration
Target configuration, egress, and isolation on the proposed deployment.
Pending verification
Operations & assurance
Incident and support operation, independent penetration testing, and workforce and supplier assurance.
Pending approval
Final review
Legal, privacy, security, and management launch decisions.
05 / Claims boundary
Certifications & regulatory status
Standards and laws require scope-specific assessment. This page is not that assessment.
Not currently claimed
- ISO/IEC 27001 certification is not currently claimed.
- No universal GDPR compliance claim is made.
- No universal NIS2, DORA, or CRA compliance claim is made.
- No CIS certification or compliance claim is made.
Conditional regulatory applicability is determined separately and is not established by this page.
06 / Further information
Documentation & security reporting
Explore the public documentation and source repository. Please report a suspected vulnerability privately.
Last reviewed: . Public statements are reviewed and updated when the underlying evidence, service scope, or approval state changes.