Security Policy
This Security Policy summarizes how Elite Business Launch approaches protection of the multi-tenant SaaS platform and customer data.
Security principles
We design for defense in depth: authentication controls, authorization (RBAC), tenant isolation, encrypted transport (HTTPS), and operational logging.
Authentication and access
Passwords are stored as irreversible hashes. Session management, email verification, optional MFA, and role-based permissions help limit access to organization data.
Payments
Card payments are processed by Stripe. We do not store full card numbers on Elite Business Launch servers.
Application and infrastructure controls
We apply rate limiting, CSRF origin checks on authenticated mutations, CAPTCHA on public abuse-prone endpoints when configured, and least-privilege access patterns for staff tools.
Incident response
Suspected security incidents should be reported to support@elitebusinesslaunch.com. We investigate and notify affected customers as required by applicable law and contractual commitments.
Customer responsibilities
Organization admins must manage user access carefully, keep devices updated, and avoid sharing credentials. See also /security for our public Security overview.
Contact
Questions about this policy: support@elitebusinesslaunch.com or our Support Center at /support.