Encryption
All data is encrypted in transit using TLS 1.2 or higher. Stored data is encrypted at rest using AES-256.
Access control
Access to client and contact data is restricted to authorized personnel under least-privilege. Multi-factor authentication is mandatory for all internal systems.
Infrastructure
Our infrastructure runs on SOC 2-certified providers. We patch systems regularly and run continuous vulnerability scanning across our stack.
Auditing
Regular third-party security audits are conducted. Penetration testing is performed at least annually. Audit reports are available to clients on request under NDA.
Incident response
Defined incident-response procedures with named owners and 24-hour notification commitment to affected clients in the event of a confirmed data breach.
Contact
For security questions or to report a vulnerability, email info@b2bleo.com.