Security
Incident Response Policy
Security and privacy incidents are triaged, contained, investigated, remediated, documented, and communicated when required.
Status: Published
Last reviewed: June 21, 2026
Owner: Leo Infinity product owner
Text to paste
Answer: YesYes. Leo Infinity has a published incident-response policy defining intake, triage, containment, credential rotation, investigation, remediation, documentation, and seller/regulatory communication when required. The reporting channel is vendas@leo.com.vc. Evidence: https://app.leo.com.vc/seguranca/incident-response-policy
Policy controls
- Intake: receive reports through the published privacy/security contact.
- Triage: classify severity by data type, affected sellers, API tokens, and service availability.
- Containment: revoke sessions, rotate secrets, pause affected integrations, or disable risky features when needed.
- Recovery: patch the issue, verify logs, document root cause, and notify affected parties when legally or contractually required.
Evidence notes
- Public incident-response page lists roles and communication channel.
- The application supports disconnecting marketplace integrations.
- Credentials are stored in systems where rotation can be performed without code changes.
