How we keep your customer data safe.
Last updated: 2026-09-03
Your business runs on the trust your customers place in you. We treat their data, and yours, with the seriousness that trust deserves. This page is a plain-English breakdown of how LeadsLockAI is built and what we do (and explicitly do not do) with your data.
Infrastructure providers
We did not build a data center. We built a focused product on top of established infrastructure providers. Their own security and compliance documentation is available directly from each provider.
- Supabase stores business profiles, leads, and conversation history in Postgres and supports operator authentication.
- Vercel hosts the web application and API routes.
- Stripe handles subscription checkout and card data; card numbers do not pass through LeadsLockAI application servers.
Data hosting
Our primary Supabase project lives in the us-west-2 region (Oregon, United States). That is where business records, lead contact details, and conversation history are stored. We apply the privacy commitments described below regardless of hosting region.
Some downstream services (Stripe and Groq for AI inference) are based in the United States. The specifics of what is shared with each are documented in our Privacy Policy.
Encryption
- In transit: The public application is served over HTTPS and includes HSTS response headers.
- At rest: Database and hosting protections are managed by our infrastructure providers under their published controls.
- Passwords: We never store plaintext passwords. All account passwords are hashed with bcrypt and a per-user salt before they touch the database.
- API keys and webhook secrets: Production credentials are supplied through protected deployment environment variables and are not committed to source code.
Webhook integrity
Anyone can send a POST to a webhook URL. We verify that the request actually came from the service that claims to have sent it.
- Stripe webhooks are verified with
stripe-signaturebefore any subscription or billing state is updated. Replays are caught by an idempotent event log. - Twilio webhooks are signature-verified when phone and SMS features are configured. Those features remain disabled until a verified Twilio setup is connected.
Security headers
Every page we serve includes:
- Strict-Transport-Security (HSTS) so the browser forces HTTPS on every future request.
- Content-Security-Policy (CSP) limiting which scripts and assets can load.
- Cross-Origin-Opener-Policy (COOP) to isolate browser context and block side-channel attacks.
- X-Frame-Options + X-Content-Type-Options to block clickjacking and MIME confusion.
Your data, your control
You own everything you put in. You can:
- Export your business profile, leads, and conversation history at any time. Email support@leadslockai.com to request an export.
- Request account deletion. We verify the request and process it subject to operational, billing, security, and legal retention needs.
What we DON'T do
- We never sell your data. Not to advertisers, not to data brokers, not to anyone. There is no business model behind that.
- We do not sell lead data. We disclose the service providers that process data for hosting, AI, billing, communications, and support in our Privacy Policy.
- We do not use lead conversations to train a LeadsLockAI public model. Conversation content is sent to the configured AI provider when a reply or extraction is generated.
- We never run ad-tracking pixels. No Meta Pixel, no Google Ads tag, no third-party analytics beyond aggregate Vercel pageviews.
Security FAQ
Is LeadsLockAI SOC 2 certified?
No. LeadsLockAI is not currently SOC 2 certified. Customers should evaluate the product's controls and the current security documentation for each infrastructure provider.
Are you HIPAA compliant?
No. LeadsLockAI is not designed for protected health information (PHI), does not offer a Business Associate Agreement, and should not be used for workflows that require HIPAA compliance.
Are you GDPR compliant?
LeadsLockAI does not currently represent that the service is GDPR compliant and does not offer a Data Processing Addendum. Contact us before using the product for EU or UK personal data.
What happens if there is a security breach?
We investigate suspected incidents, preserve evidence, contain the issue, and notify affected parties and regulators when required by applicable law. Timing depends on the facts and legal requirements.
How do I report a vulnerability?
Email security@leadslockai.com. We review responsible disclosures in good faith. We do not currently operate a paid bug-bounty program.
Audit history
Last application security review: 2026-09-03. We run security reviews on a rolling basis and ship hardening updates as a normal part of the release cycle. See our public changelog for the most recent security-tagged entries.
Contact
Security questions: security@leadslockai.com. General privacy questions: support@leadslockai.com.