Trust Center

Security, Privacy & Operational Transparency

This page summarizes how Snatchool Innovations LLC protects data, controls access, and responds to security events across the SP Slim™ customer portal, partner portal, and enterprise services. It is maintained by Snatchool to answer common security and privacy questions about our platform.

Security Overview

We design, build, and operate the Service to support security best practices across identity, data, application, and infrastructure layers. Snatchool Innovations LLC does not currently hold formal certifications.

Data Handling

Data in transit is protected with HTTPS/TLS. The managed database provides encryption at rest. Sensitive server credentials are stored only as environment secrets on the hosting platform.

Access Controls

Portal access uses a managed identity provider with password and OAuth sign-in. Sessions are validated on every server call. Admin routes require an elevated role.

Role-Based Permissions

Roles live in a dedicated table with row-level security. Server functions verify the caller's role before performing privileged actions.

Audit Logs

Sensitive administrative actions are recorded to an activity log accessible to authorized staff.

Backups

The managed database performs automated backups on the schedule provided by our hosting platform.

Incident Response

We follow a documented incident-response process to detect, contain, and communicate confirmed security incidents. See our Incident Response Policy.

Responsible Disclosure

If you believe you have discovered a security vulnerability in Snatchool's services, email security@snatchool.net with a description, steps to reproduce, and any relevant proof-of-concept. Please give us a reasonable window to remediate before public disclosure. We do not currently offer a monetary bug bounty.

Policies

Snatchool Innovations LLC designs its platform to support security best practices commonly reflected in frameworks such as SOC 2 and ISO 27001. We do not currently claim any certification under those frameworks. Nothing on this page constitutes legal advice.