Security and messaging compliance are built into how LeadCoda works, not bolted on. Here is exactly where we stand, with nothing overstated.
All traffic between you, your leads, and LeadCoda is encrypted in transit.
Databases are encrypted at rest, and API keys and tokens get an extra layer of application-level encryption.
Per-lead SMS consent records, STOP opt-outs honored automatically, quiet hours enforced.
Unsubscribe links are enforced on every marketing email, and opt-outs stop sequences instantly.
Data export and deletion on request, a signable DPA, and documented subprocessors.
We never sell personal information. Know, access, and delete rights honored.
Card details go straight to Stripe and never touch LeadCoda servers.
Workspace data is isolated per customer, and sessions use signed, httpOnly cookies.
Every lead carries its own email and SMS consent record with a timestamp. Sequences check consent before every single send. A STOP reply or an unsubscribe click halts messaging to that lead immediately, across every sequence, and the product will not let an SMS-first template ship without opt-out language. Imported lists carry per-row consent so old spreadsheets cannot silently become spam.
You own your workspace data and can export it or ask for deletion at any time. We never sell personal information and never use your leads to advertise or to train anything. When you connect an integration, its credentials are encrypted with application-level encryption before they are stored, and they are only decrypted at the moment of use.
LeadCoda runs on a small, deliberate set of infrastructure providers. Each one processes data only for the purpose listed.
| Provider | Purpose | Region |
|---|---|---|
| Vercel | Application hosting | United States |
| Neon | Database (PostgreSQL) | United States |
| Resend | Email delivery | United States |
| Twilio | SMS delivery | United States |
| Stripe | Payments and billing | United States |
| Meta Platforms | Lead ads sync (only when you connect it) | United States |
SOC 2 Type II certification is planned as we grow. We only display badges we have actually earned, so you will see it here the day the audit completes and not a day before. In the meantime our practices above are written to align with SOC 2 trust principles from day one.
We welcome responsible disclosure. Email security@leadcoda.app and we will respond within two business days.
See also our Privacy Policy, Terms of Service, and Data Processing Agreement.