Enterprise Security
Last reviewed: June 2025
LeadRadar AI is built with security as a foundation, not an afterthought. We use the same encryption, access controls, and monitoring practices as leading enterprise SaaS companies.
What we protect
Our commitments
Encryption
- AES-256 encryption for all data at rest
- TLS 1.3 encryption for all data in transit
- End-to-end encrypted data pipeline
- Encrypted database backups with separate key management
- Secrets stored in environment variables — never in code
Infrastructure Security
- Hosted on enterprise-grade cloud infrastructure (Supabase, Vercel)
- Automatic scaling with DDoS protection
- Geographically distributed with redundant backups
- Automated daily database backups with point-in-time recovery
- Zero-downtime deployments via continuous delivery pipeline
Authentication & Access
- Secure JWT-based authentication via Supabase Auth
- Bcrypt password hashing — we never store plain-text passwords
- Email verification required for all new accounts
- Session expiry and automatic logout on inactivity
- Multi-factor authentication (MFA) available for all accounts
Access Controls
- Row-Level Security (RLS) enforced at database level
- Complete data isolation between tenants — no cross-account data access
- Role-based access control (Owner, Admin, Member) for team workspaces
- Principle of least privilege applied to all internal systems
- API key scoping with per-key permission controls
Data Retention
- Data retained only as long as your account is active
- Account deletion triggers permanent data erasure within 30 days
- Anonymised usage statistics retained for platform improvement
- Billing records retained per legal requirements (7 years)
- You can export all your data at any time from account settings
Incident Response
- 24/7 automated security monitoring with alerting
- Data breach notification within 72 hours of discovery
- Documented incident response procedures tested quarterly
- Post-incident review and public disclosure for material incidents
- Real-time status page at status.leadradar.live
Payment Security
All payments on LeadRadar are processed by PayU India, a PCI DSS Level 1 certified payment processor. We never transmit or store your card number, CVV, or expiry date on our servers. The payment form is hosted entirely by PayU on their secure infrastructure.
We receive only a masked payment confirmation (last 4 digits, transaction ID, and status) to activate your subscription. This means even in the unlikely event of a breach of our systems, your financial data would remain uncompromised.
Compliance & Standards
Full compliance with EU General Data Protection Regulation
Aligned with India's Personal Data Protection Bill requirements
Email outreach tools designed for anti-spam compliance
Payment processing via PCI DSS certified provider (PayU)
Infrastructure built to SOC 2 standards via Supabase/Vercel
Latest transport security protocol for all connections
Report a Vulnerability
If you discover a security vulnerability in LeadRadar, please report it responsibly. Do not disclose it publicly until we have had a chance to address it.
Email our security team at rahulkarthik1998@gmail.com. We acknowledge all reports within 48 hours and aim to resolve critical issues within 7 days. We appreciate responsible disclosure.