Security is built into LeadZapp at every layer. This statement summarizes how we protect your data and keep the platform reliable.
The platform runs on established cloud providers with hardened, regularly patched environments. Production access is restricted and audited.
All traffic is encrypted in transit with TLS. Sensitive data, including lead PII (emails, phones), is encrypted at rest. Secrets are held in a managed vault, never in source control.
Role-based access controls limit what each user can do. Multi-factor authentication is mandatory for platform staff, and all privileged access is logged.
Every customer's data is isolated by a tenant identifier enforced at the application layer, and validated by an automated "tenant-leak" test suite that blocks release if any cross-tenant access is detected.
We maintain structured logs, error tracking, and metrics across the application and the lead-generation engine, with an immutable audit log of sensitive actions.
We patch dependencies, review code, and remediate findings on a risk-prioritized basis.
Databases are backed up regularly with tested restore procedures to support business continuity.
If you believe you've found a security issue, email [email protected]. We appreciate responsible disclosure and will respond promptly.