Third Party Index

Snapshot 36114

Document
Security page
URL
https://leadjourney.io/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
785041 bytes
SHA-256 (raw)
1fad24d283f113a2e637d97a6cfcc37bb04f80fe97e2f1f2edcd05e9613e2876
SHA-256 (normalized text)
0e44ea6bc000930eba37846567589b0e2822007bea2d389969df26fbf0fe1fee

Normalized text

Scripts and page chrome removed; this is what change detection compares.

The MCP server is liveyour attribution data, answering in Claude, ChatGPT and any AI assistantConnect yours
Security
Security built for your revenue data
We hold your ad spend, lead records, pipeline and revenue. Encryption throughout the stack, strict access controls, EU hosting, privacy by design.
AES-256 at rest
TLS in transit
EU hosting (Frankfurt)
Two-factor auth
Signed webhooks
GDPR and DPA
Book a demoStart free trial
Or click through the live demo23 screens, no signup
Rated by the teams who trust us with their data
Google
TrustpilotRated 4.9 out of 5 on Trustpilot4.9
G2Rated 5.0 out of 5 on G25.0
CapterraRated 5.0 out of 5 on Capterra5.0
Trusted by 100+ lead generation businesses, agencies and freelancers
Defence in depth
Protection at every layer of the stack
Security is not one control, it is many working together. Here is how we protect access, data, infrastructure and operations.
Access and identity
Two-factor authentication (TOTP)
Enforced password complexity
bcrypt password hashing, 12 rounds
Token and Redis backed sessions
Encryption
AES-256 at rest for sensitive data
TLS enforced in transit
Encrypted OAuth and 2FA secrets
Encrypted recovery codes
Infrastructure
Hosted in Frankfurt, Germany (EU)
Kubernetes orchestrated services
Least privilege across services
Encrypted credentials at rest
Monitoring
Exception and performance monitoring
Centralised log aggregation
Real-time alerting to the team
Signed, verified inbound webhooks
Access and authentication
Only the right people get in
Every account is protected by modern authentication, and access to production systems follows the principle of least privilege.
Two-factor authentication
TOTP based 2FA, for example Google Authenticator, with encrypted recovery codes so a lost device never means a lost account.
Passwords
Enforced complexity: a minimum length with upper and lower case, numbers and symbols. Hashed with bcrypt at 12 rounds, never stored in plain text.
Sessions and tokens
API access uses Laravel Sanctum tokens, with sessions backed by Redis for fast, controlled invalidation.
Integrations
Connected platforms authorise through OAuth 2.0, so we never handle the credentials of your ad and marketing accounts.
Encryption
Encrypted in transit and at rest
Data is protected on the wire and in the database, with the most sensitive fields encrypted individually.
In transit
All traffic is served over HTTPS and TLS in production. Nothing sensitive travels unencrypted.
At rest
AES-256-CBC encryption for OAuth tokens, two-factor secrets and personal data held in the database.
Secrets management
Application secrets are managed through environment configuration. Integration tokens and webhook secrets are encrypted in the database.
Credentials
Credentials are never stored in plain text and are held with least privilege scope across services.
Infrastructure and data residency
Hosted in the EU, in Frankfurt
We chose EU based infrastructure so European teams keep their core data in the European Union by default.
Location
Production infrastructure is located in Frankfurt, Germany, inside the European Union.
Platform
Services run on Kubernetes: MySQL, Redis and Soketi for realtime, orchestrated as isolated, least privilege services.
File storage
Uploaded files are stored on Amazon S3.
Sub-processors
We keep a current, public list of every sub-processor with access to data on our GDPR page.
Integrations and webhooks
Verified data in, secrets out of reach
LeadJourney connects to your ad platforms and tools. Those connections are authenticated, and everything flowing into the platform is verified.
Signed webhooks
Every inbound webhook is verified with an HMAC-SHA256 or Ed25519 signature before it is accepted, so forged events are rejected.
Encrypted tokens
Integration tokens and webhook secrets are encrypted in the database, separate from the rest of your data.
Logging and monitoring
Watched around the clock
We watch for errors, performance regressions and anomalies, with alerts routed to the team in real time.
Exceptions and performance
Application errors and performance are monitored with Laravel Nightwatch.
Centralised logs
Logs are aggregated centrally in LogDNA for search and investigation.
Alerting
Alerts are pushed to Slack so issues reach the team quickly.
Privacy and compliance
Privacy is built in, not bolted on
LeadJourney is built for European marketing and revenue teams, so data protection is part of the foundation.
GDPR
EU data residency, lawful basis tracking, sub-processor transparency and full data subject rights. See our GDPR and data protection page.
Data Processing Agreement
An Art. 28 GDPR compliant DPA is available on request to customers who process personal data through LeadJourney.
Data Protection Officer
We have an appointed DPO, reachable at [email protected].
First-party tracking
LeadJourney is built on first-party, server-side tracking, which cuts the reliance on third-party cookies.
Responsible disclosure
Found something? We want to hear from you
If you believe you have found a security vulnerability, please tell us before disclosing it publicly. Email the details and the steps to reproduce, and we will come back to you quickly. We will not pursue legal action against good faith researchers who report responsibly.
[email protected]
We aim to respond quickly and to keep you updated until the report is closed.
FAQ
The questions security teams ask us
Everything a vendor review usually asks, answered here so you do not have to send the questionnaire first.
Where is my data stored?
All production infrastructure runs in Frankfurt, Germany, inside the European Union. Application, database (MySQL), cache (Redis) and realtime (Soketi) services run on Kubernetes there, and file storage is on Amazon S3. European customers keep their core data in the EU by default.
Is my data encrypted?
Yes. All traffic is served over HTTPS and TLS in production. Sensitive data, including OAuth tokens, two-factor secrets and personal data, is encrypted at rest with AES-256.
Do you support two-factor authentication?
Yes. LeadJourney supports TOTP based two-factor authentication, for example Google Authenticator, with encrypted recovery codes.
How are passwords stored?
Passwords must meet complexity rules (minimum length, upper and lower case, numbers and symbols) and are hashed with bcrypt at 12 rounds. We never store passwords in plain text.
Do you support SAML single sign-on?
Not yet. We use OAuth 2.0 for connected integrations, but SAML single sign-on for user login is not available. If your team needs it, contact us and tell us about your requirements.
How do you secure integrations and webhooks?
Integration tokens and webhook secrets are encrypted in the database, and secrets are managed through environment configuration. Every inbound webhook is verified with an HMAC-SHA256 or Ed25519 signature before it is processed.
Do you offer a Data Processing Agreement?
Yes. If you process personal data through LeadJourney, we make a DPA available on request that meets the requirements of Art. 28 GDPR. Email [email protected] and we will send it.
Are you GDPR compliant?
Yes. We host in the EU, publish a list of sub-processors, support data subject rights and have an appointed Data Protection Officer. The full detail is on our GDPR and data protection page.
Passing a security review
We will help your team through procurement
Ask for the security overview, the DPA and our technical and organisational measures in one email, and we will send the set.
Book a demoStart free trial
Or click through the live demo23 screens, no signup