Legal · Snatchool Innovations LLC
Security Policy
Last updated: July 3, 2026
Snatchool Innovations LLC designs, builds, and operates the Service to support security best practices across identity, data, application, and infrastructure layers.
Identity & Access
Portal authentication uses a managed identity provider with password and OAuth options. Roles are stored in a dedicated table and enforced through row-level security. Sessions are protected in transit with HTTPS/TLS.
Data Protection
Data in transit is protected with TLS. Storage of sensitive fields relies on the managed database's encryption at rest. Sensitive server credentials are held only as environment secrets on the hosting platform.
Application Security
Input is validated with strict schemas server-side. Uploads are validated for file type, size, and dimensions. Rate limits are applied at the platform edge.
Infrastructure
The Service runs on a serverless edge runtime with automatic HTTPS provisioning and DDoS protection provided by the hosting platform.
Logging & Monitoring
Sensitive administrative actions are recorded to an audit log accessible to authorized staff.
Vulnerability Management
See our Responsible Disclosure Contact.
Compliance-Readiness
The Service is designed to support security best practices commonly reflected in frameworks such as SOC 2 and ISO 27001. Snatchool Innovations LLC does not currently claim any certification under those frameworks.
Questions about this policy?
Contact Snatchool Innovations LLC at legal@snatchool.net or 954-861-9922.
This document is provided for informational purposes and is not legal advice. Snatchool Innovations LLC recommends reviewing these terms with qualified counsel before relying on them for contractual purposes.