← Back to Home

Enterprise Security

Last reviewed: June 2025

LeadRadar AI is built with security as a foundation, not an afterthought. We use the same encryption, access controls, and monitoring practices as leading enterprise SaaS companies.

What we protect

Your account credentials and personal information
Lead data you discover and store
AI-generated content and outreach history
Team member information
Payment transaction data

Our commitments

We never sell your data to third parties
We never store your payment card details
We notify you within 72 hours of any breach
You can delete your account and all data at any time
All sub-processors meet our security standards

Encryption

  • AES-256 encryption for all data at rest
  • TLS 1.3 encryption for all data in transit
  • End-to-end encrypted data pipeline
  • Encrypted database backups with separate key management
  • Secrets stored in environment variables — never in code

Infrastructure Security

  • Hosted on enterprise-grade cloud infrastructure (Supabase, Vercel)
  • Automatic scaling with DDoS protection
  • Geographically distributed with redundant backups
  • Automated daily database backups with point-in-time recovery
  • Zero-downtime deployments via continuous delivery pipeline

Authentication & Access

  • Secure JWT-based authentication via Supabase Auth
  • Bcrypt password hashing — we never store plain-text passwords
  • Email verification required for all new accounts
  • Session expiry and automatic logout on inactivity
  • Multi-factor authentication (MFA) available for all accounts

Access Controls

  • Row-Level Security (RLS) enforced at database level
  • Complete data isolation between tenants — no cross-account data access
  • Role-based access control (Owner, Admin, Member) for team workspaces
  • Principle of least privilege applied to all internal systems
  • API key scoping with per-key permission controls

Data Retention

  • Data retained only as long as your account is active
  • Account deletion triggers permanent data erasure within 30 days
  • Anonymised usage statistics retained for platform improvement
  • Billing records retained per legal requirements (7 years)
  • You can export all your data at any time from account settings

Incident Response

  • 24/7 automated security monitoring with alerting
  • Data breach notification within 72 hours of discovery
  • Documented incident response procedures tested quarterly
  • Post-incident review and public disclosure for material incidents
  • Real-time status page at status.leadradar.live

Payment Security

All payments on LeadRadar are processed by PayU India, a PCI DSS Level 1 certified payment processor. We never transmit or store your card number, CVV, or expiry date on our servers. The payment form is hosted entirely by PayU on their secure infrastructure.

We receive only a masked payment confirmation (last 4 digits, transaction ID, and status) to activate your subscription. This means even in the unlikely event of a breach of our systems, your financial data would remain uncompromised.

Compliance & Standards

GDPR

Full compliance with EU General Data Protection Regulation

India PDPB

Aligned with India's Personal Data Protection Bill requirements

CAN-SPAM

Email outreach tools designed for anti-spam compliance

PCI DSS

Payment processing via PCI DSS certified provider (PayU)

SOC 2 Ready

Infrastructure built to SOC 2 standards via Supabase/Vercel

TLS 1.3

Latest transport security protocol for all connections

Report a Vulnerability

If you discover a security vulnerability in LeadRadar, please report it responsibly. Do not disclose it publicly until we have had a chance to address it.

Email our security team at rahulkarthik1998@gmail.com. We acknowledge all reports within 48 hours and aim to resolve critical issues within 7 days. We appreciate responsible disclosure.