Control overview
Leadping does not publish implementation details that would materially increase attack risk.
Encryption and data movement
Customer data is encrypted in transit using HTTPS/TLS and at rest using managed infrastructure protections. Encryption operates alongside authentication, authorization, isolation, monitoring, and restricted production access. Customers must use HTTPS for systems they control, including posting integrations and webhook receivers. Exported data is no longer protected by Leadping access controls and must be secured by the customer.Access and isolation
- User access follows organization membership and role.
- API access follows the authenticated user, organization, agent, or source context.
- Resource checks prevent a valid credential from receiving unrelated access.
- Production access is restricted to authorized personnel and providers with a business need.
- Access can be revoked, rotated, or restricted when risk is detected or access is no longer required.
Credentials
Treat API keys, source keys, access tokens, refresh tokens, webhook secrets, and integration credentials as confidential.- Store secrets in protected runtime configuration or a secret manager.
- Use separate credentials when traceability or independent rotation matters.
- Grant only the required access.
- Rotate exposed or misdirected credentials immediately.
- Never place secrets in lead metadata, URLs, screenshots, support messages, analytics, or public repositories.
Monitoring and response
Leadping records and monitors security-relevant signals needed to operate and protect the service. Depending on the event, those signals may include authentication, API behavior, provider feedback, delivery behavior, suspected abuse, and unusual usage. When investigating an incident, Leadping works to:- contain the issue;
- protect affected systems and accounts;
- preserve useful evidence;
- restore normal operation; and
- make notifications required by applicable obligations.
Service providers
Leadping uses established providers for infrastructure and platform functions. Provider access is limited to the role needed to deliver the service. See Subprocessors.Customer responsibilities
Customers should:- protect credentials and account-recovery channels;
- review users and roles regularly;
- remove access promptly when it is no longer needed;
- secure forms, publishers, CRMs, webhooks, exports, and local copies;
- validate webhook signatures;
- collect only the information needed for the workflow; and
- report suspected access or credential exposure quickly.

