LeadCoda
๐Ÿ” Trust & Security

Your leads are your business. We treat them that way.

Security and messaging compliance are built into how LeadCoda works, not bolted on. Here is exactly where we stand, with nothing overstated.

๐Ÿ”’

TLS 1.2+ everywhere

All traffic between you, your leads, and LeadCoda is encrypted in transit.

๐Ÿ—„๏ธ

Encrypted at rest

Databases are encrypted at rest, and API keys and tokens get an extra layer of application-level encryption.

๐Ÿ“ต

TCPA-aware texting

Per-lead SMS consent records, STOP opt-outs honored automatically, quiet hours enforced.

๐Ÿ“ง

CAN-SPAM compliant email

Unsubscribe links are enforced on every marketing email, and opt-outs stop sequences instantly.

๐Ÿ‡ช๐Ÿ‡บ

GDPR-ready

Data export and deletion on request, a signable DPA, and documented subprocessors.

๐Ÿ›ก๏ธ

CCPA-ready

We never sell personal information. Know, access, and delete rights honored.

๐Ÿ’ณ

PCI DSS payments via Stripe

Card details go straight to Stripe and never touch LeadCoda servers.

๐Ÿ”‘

Least-privilege access

Workspace data is isolated per customer, and sessions use signed, httpOnly cookies.

Consent is enforced by the product

Every lead carries its own email and SMS consent record with a timestamp. Sequences check consent before every single send. A STOP reply or an unsubscribe click halts messaging to that lead immediately, across every sequence, and the product will not let an SMS-first template ship without opt-out language. Imported lists carry per-row consent so old spreadsheets cannot silently become spam.

Your data stays yours

You own your workspace data and can export it or ask for deletion at any time. We never sell personal information and never use your leads to advertise or to train anything. When you connect an integration, its credentials are encrypted with application-level encryption before they are stored, and they are only decrypted at the moment of use.

Subprocessors

LeadCoda runs on a small, deliberate set of infrastructure providers. Each one processes data only for the purpose listed.

ProviderPurposeRegion
VercelApplication hostingUnited States
NeonDatabase (PostgreSQL)United States
ResendEmail deliveryUnited States
TwilioSMS deliveryUnited States
StripePayments and billingUnited States
Meta PlatformsLead ads sync (only when you connect it)United States

On our roadmap, stated honestly

SOC 2 Type II certification is planned as we grow. We only display badges we have actually earned, so you will see it here the day the audit completes and not a day before. In the meantime our practices above are written to align with SOC 2 trust principles from day one.

Found something?

We welcome responsible disclosure. Email security@leadcoda.app and we will respond within two business days.

See also our Privacy Policy, Terms of Service, and Data Processing Agreement.