Snapshot 36114
Normalized text
Scripts and page chrome removed; this is what change detection compares.
The MCP server is liveyour attribution data, answering in Claude, ChatGPT and any AI assistantConnect yours Security Security built for your revenue data We hold your ad spend, lead records, pipeline and revenue. Encryption throughout the stack, strict access controls, EU hosting, privacy by design. AES-256 at rest TLS in transit EU hosting (Frankfurt) Two-factor auth Signed webhooks GDPR and DPA Book a demoStart free trial Or click through the live demo23 screens, no signup Rated by the teams who trust us with their data Google TrustpilotRated 4.9 out of 5 on Trustpilot4.9 G2Rated 5.0 out of 5 on G25.0 CapterraRated 5.0 out of 5 on Capterra5.0 Trusted by 100+ lead generation businesses, agencies and freelancers Defence in depth Protection at every layer of the stack Security is not one control, it is many working together. Here is how we protect access, data, infrastructure and operations. Access and identity Two-factor authentication (TOTP) Enforced password complexity bcrypt password hashing, 12 rounds Token and Redis backed sessions Encryption AES-256 at rest for sensitive data TLS enforced in transit Encrypted OAuth and 2FA secrets Encrypted recovery codes Infrastructure Hosted in Frankfurt, Germany (EU) Kubernetes orchestrated services Least privilege across services Encrypted credentials at rest Monitoring Exception and performance monitoring Centralised log aggregation Real-time alerting to the team Signed, verified inbound webhooks Access and authentication Only the right people get in Every account is protected by modern authentication, and access to production systems follows the principle of least privilege. Two-factor authentication TOTP based 2FA, for example Google Authenticator, with encrypted recovery codes so a lost device never means a lost account. Passwords Enforced complexity: a minimum length with upper and lower case, numbers and symbols. Hashed with bcrypt at 12 rounds, never stored in plain text. Sessions and tokens API access uses Laravel Sanctum tokens, with sessions backed by Redis for fast, controlled invalidation. Integrations Connected platforms authorise through OAuth 2.0, so we never handle the credentials of your ad and marketing accounts. Encryption Encrypted in transit and at rest Data is protected on the wire and in the database, with the most sensitive fields encrypted individually. In transit All traffic is served over HTTPS and TLS in production. Nothing sensitive travels unencrypted. At rest AES-256-CBC encryption for OAuth tokens, two-factor secrets and personal data held in the database. Secrets management Application secrets are managed through environment configuration. Integration tokens and webhook secrets are encrypted in the database. Credentials Credentials are never stored in plain text and are held with least privilege scope across services. Infrastructure and data residency Hosted in the EU, in Frankfurt We chose EU based infrastructure so European teams keep their core data in the European Union by default. Location Production infrastructure is located in Frankfurt, Germany, inside the European Union. Platform Services run on Kubernetes: MySQL, Redis and Soketi for realtime, orchestrated as isolated, least privilege services. File storage Uploaded files are stored on Amazon S3. Sub-processors We keep a current, public list of every sub-processor with access to data on our GDPR page. Integrations and webhooks Verified data in, secrets out of reach LeadJourney connects to your ad platforms and tools. Those connections are authenticated, and everything flowing into the platform is verified. Signed webhooks Every inbound webhook is verified with an HMAC-SHA256 or Ed25519 signature before it is accepted, so forged events are rejected. Encrypted tokens Integration tokens and webhook secrets are encrypted in the database, separate from the rest of your data. Logging and monitoring Watched around the clock We watch for errors, performance regressions and anomalies, with alerts routed to the team in real time. Exceptions and performance Application errors and performance are monitored with Laravel Nightwatch. Centralised logs Logs are aggregated centrally in LogDNA for search and investigation. Alerting Alerts are pushed to Slack so issues reach the team quickly. Privacy and compliance Privacy is built in, not bolted on LeadJourney is built for European marketing and revenue teams, so data protection is part of the foundation. GDPR EU data residency, lawful basis tracking, sub-processor transparency and full data subject rights. See our GDPR and data protection page. Data Processing Agreement An Art. 28 GDPR compliant DPA is available on request to customers who process personal data through LeadJourney. Data Protection Officer We have an appointed DPO, reachable at [email protected]. First-party tracking LeadJourney is built on first-party, server-side tracking, which cuts the reliance on third-party cookies. Responsible disclosure Found something? We want to hear from you If you believe you have found a security vulnerability, please tell us before disclosing it publicly. Email the details and the steps to reproduce, and we will come back to you quickly. We will not pursue legal action against good faith researchers who report responsibly. [email protected] We aim to respond quickly and to keep you updated until the report is closed. FAQ The questions security teams ask us Everything a vendor review usually asks, answered here so you do not have to send the questionnaire first. Where is my data stored? All production infrastructure runs in Frankfurt, Germany, inside the European Union. Application, database (MySQL), cache (Redis) and realtime (Soketi) services run on Kubernetes there, and file storage is on Amazon S3. European customers keep their core data in the EU by default. Is my data encrypted? Yes. All traffic is served over HTTPS and TLS in production. Sensitive data, including OAuth tokens, two-factor secrets and personal data, is encrypted at rest with AES-256. Do you support two-factor authentication? Yes. LeadJourney supports TOTP based two-factor authentication, for example Google Authenticator, with encrypted recovery codes. How are passwords stored? Passwords must meet complexity rules (minimum length, upper and lower case, numbers and symbols) and are hashed with bcrypt at 12 rounds. We never store passwords in plain text. Do you support SAML single sign-on? Not yet. We use OAuth 2.0 for connected integrations, but SAML single sign-on for user login is not available. If your team needs it, contact us and tell us about your requirements. How do you secure integrations and webhooks? Integration tokens and webhook secrets are encrypted in the database, and secrets are managed through environment configuration. Every inbound webhook is verified with an HMAC-SHA256 or Ed25519 signature before it is processed. Do you offer a Data Processing Agreement? Yes. If you process personal data through LeadJourney, we make a DPA available on request that meets the requirements of Art. 28 GDPR. Email [email protected] and we will send it. Are you GDPR compliant? Yes. We host in the EU, publish a list of sub-processors, support data subject rights and have an appointed Data Protection Officer. The full detail is on our GDPR and data protection page. Passing a security review We will help your team through procurement Ask for the security overview, the DPA and our technical and organisational measures in one email, and we will send the set. Book a demoStart free trial Or click through the live demo23 screens, no signup