Security
How we protect your data
1. Our Commitment to Security
At Leniqo, security is foundational to everything we build. As a platform that handles sensitive rental, financial and identity data, we apply rigorous technical and organisational measures to protect the confidentiality, integrity and availability of all data processed through our systems.
This page provides an overview of our security practices. It is intended for transparency and does not constitute a contractual commitment.
2. Infrastructure & Hosting
Our platform infrastructure is designed for security, scalability and resilience:
- Hosted on enterprise-grade cloud infrastructure within the European Union;
- Data residency within EEA-compliant regions;
- Redundant systems with automated failover and disaster recovery;
- Network isolation with firewalls, VPCs and restricted access controls;
- Real-time infrastructure monitoring and automated alerting.
3. Data Encryption
All data is protected using industry-standard encryption:
- Data in transit: TLS 1.2+ encryption for all communications between clients and servers;
- Data at rest: AES-256 encryption for stored data, including databases and file storage;
- Encryption key management through managed cloud services with regular key rotation.
4. Access Control
We enforce strict access controls across all systems:
- Role-based access control (RBAC) with principle of least privilege;
- Multi-factor authentication (MFA) required for all internal accounts;
- Session management with automatic timeout and inactivity lock;
- Regular access reviews and prompt deprovisioning of departed personnel;
- Audit logging of all administrative actions.
5. Application Security
Our development practices incorporate security at every stage:
- Secure development lifecycle (SDLC) with security reviews;
- Input validation, parameterised queries and protection against OWASP Top 10 vulnerabilities;
- Content Security Policy (CSP) and other HTTP security headers;
- Dependency scanning and vulnerability monitoring for third-party packages;
- Rate limiting and abuse prevention on all API endpoints.
6. Data Protection & Privacy
Security and privacy are complementary disciplines at Leniqo:
- Data minimisation: we only collect and process data that is necessary for our services;
- Purpose limitation: data is processed only for specified, legitimate purposes;
- Retention policies: data is deleted or anonymised when no longer needed;
- Privacy by design and by default in all platform features.
For full details on how we handle personal data, please refer to our Privacy Policy.
7. Incident Response
We maintain a documented incident response procedure to handle security events promptly and effectively:
- 24/7 monitoring with automated detection and alerting;
- Defined escalation procedures and response team roles;
- Containment, investigation, remediation and recovery processes;
- Post-incident review and lessons learned;
- Notification to affected parties and regulators in accordance with GDPR Article 33/34 timelines.
8. Business Continuity
Our business continuity measures ensure platform availability:
- Automated backups with point-in-time recovery;
- Geographically distributed infrastructure for redundancy;
- Disaster recovery plan with defined RTO and RPO targets;
- Regular backup restoration testing.
9. Vendor & Third-Party Security
We carefully evaluate all third-party service providers before integration:
- Due diligence review of security practices and certifications;
- Data Processing Agreements (DPAs) with all processors;
- Ongoing monitoring of vendor security posture;
- Preference for EU-based or Privacy Shield / adequacy decision-covered providers.
10. Compliance & Standards
Our security programme is aligned with recognised standards and regulations:
- General Data Protection Regulation (GDPR);
- ePrivacy Directive;
- ISO 27001 principles (information security management);
- OWASP application security standards.
11. Responsible Disclosure
We value the security research community. If you discover a potential vulnerability in our platform, please report it responsibly to security@leniqo.com. We commit to:
- Acknowledging receipt within 2 business days;
- Investigating and providing a timeline for remediation;
- Not pursuing legal action against researchers acting in good faith.
12. Contact
For security-related enquiries, please contact:
Leniqo Limited, Security Team Email: security@leniqo.com
Leniqo Limited
Company Number: 802949
The Black Church, St. Mary's Place
Dublin 7, Ireland (D07 P4AX)