Security
Endpoint Antimalware and Device Baseline
Administrative endpoints must use operating-system protection, updates, screen lock, and credential protection.
Status: Published
Last reviewed: June 21, 2026
Owner: Leo Infinity product owner
Text to paste
Answer: YesYes. Company endpoints used for production administration must use operating-system malware protection such as macOS XProtect/Gatekeeper or an equivalent vendor tool, automatic security updates, screen lock, browser credential protection, and no local storage of marketplace protected data. Compromised or lost devices trigger credential rotation. Evidence: https://app.leo.com.vc/seguranca/endpoint-antimalware-baseline
Policy controls
- Production administrators must keep operating-system security updates enabled.
- Devices must use a lock screen and must not store raw marketplace exports containing personal data unless temporarily required for support.
- Browser and password-manager access must be protected by device authentication.
- If a device is lost or suspected compromised, marketplace tokens, app sessions, and production credentials are rotated.
Evidence notes
- Endpoint baseline is published as a security requirement.
- The application avoids local client storage of protected marketplace data beyond authenticated browser sessions.
- Credential rotation is documented as part of incident response.
