Third Party Index

Snapshot 44775

Document
Security page
URL
https://leadmagic.io/company/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
browser
Size
268013 bytes
SHA-256 (raw)
7d751ce7d12d263a0d3aacd8536e09c7323d3f9094629c3668470eba2f27888f
SHA-256 (normalized text)
131f6aeac586f501ef14680faed09adddf5a02a1f33b86da1cfcf3b9adaa37f6

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Skip to main content
New
Unlimited Search is live — zero-credit People, Company & Jobs Search at 5–10 RPSUnlimited Search is live
Try Unlimited
Security & Trust
Enterprise security for your enrichment layer
LeadMagic maintains a written information security program with encryption in transit and at rest, enforced MFA on workforce and critical systems, least-privilege access, centralized logging, vendor governance, and a published Privacy Policy and DPA. We honor GDPR and CCPA/CPRA data subject requests.
Request security packView DPA
Security program
Built for teams with real compliance requirements
A defense-in-depth program for B2B data infrastructure — encryption, identity controls, monitored production, vendor governance, and published privacy policies.
Defense in depth
Layered administrative, technical, and operational controls across workforce identity, production infrastructure, APIs, and vendor integrations.
Encryption by default
TLS 1.3 for data in transit and AES-256 for data at rest across supported cloud services. Secrets managed through dedicated vaults — never committed to source control.
Identity & MFA
Google Workspace SSO with enforced 2-Step Verification for workforce access. MFA required on critical SaaS and production dashboards.
Least privilege & access reviews
Role-based access with documented joiner, mover, and leaver procedures and periodic access reviews for production systems.
Monitoring & logging
Centralized telemetry, error tracking, and audit logging to support security investigation and operational response.
Vendor & subprocessor governance
Subprocessor tracking, vendor security reviews, and DPAs with infrastructure providers that handle customer or enrichment data.
Control framework
Four pillars of our security posture
Documented policies, operational practices, and controls for teams that need clear answers during procurement and partner review.
Access & identity
Google Workspace as workforce IdP with enforced MFA
Scoped API keys and role-based permissions for customers
Production access limited to authorized engineering and operations personnel
Joiner / mover / leaver checklists with same-day deprovisioning
Data protection
TLS 1.3 in transit; AES-256 at rest where supported by underlying services
Secrets managed via Doppler and 1Password — not stored in application code
Data minimization and retention limits aligned to service delivery
Customer DPAs with Standard Contractual Clauses for international transfers
Secure operations
Production hosted on enterprise cloud infrastructure (Cloudflare, Vercel, GCP-class providers)
Change management through reviewed pull requests and controlled deployments
Vulnerability and dependency review as part of our secure development lifecycle
Incident response procedures with partner notification within contractual timelines
Privacy & compliance
Published Privacy Policy and DPA; GDPR and CCPA/CPRA data subject requests honored
Documented DSAR intake via [email protected] and /legal/privacy-request
Written information security program with administrative and technical safeguards
Responsible disclosure via [email protected] and /.well-known/security.txt
Privacy
Privacy programs & security posture
What we publish today — no inflated certification claims.
Security programDocumented administrative & technical controls
Privacy requestsGDPR & CCPA/CPRA rights honored
Privacy PolicyPublished data practices
DPA availableStandard + enterprise terms
Need a security questionnaire, subprocessor list, or custom DPA? Request documentation or email [email protected].
Responsible disclosure: report vulnerabilities to [email protected]. See security.txt for RFC 9116 contact details.
FAQ
Security FAQ
No. LeadMagic does not hold SOC 2, SOC 2 Type II, ISO 27001, or other third-party security certifications. We maintain a written information security program with encryption, access controls, vendor review, logging, and privacy processes appropriate to our services. A DPA is available for customers who need contractual assurances.
Data is encrypted in transit using TLS 1.3. Data at rest is encrypted using AES-256 across supported cloud infrastructure providers. API credentials and internal secrets are managed through dedicated secrets management — not stored in repositories or application logs.
LeadMagic primarily uses cloud infrastructure in the United States. Safeguards include encryption in transit and at rest, access controls, and vendor DPAs. Custom data residency commitments require a separate written agreement.
Yes. We provide a Data Processing Agreement for customers and partners, including Standard Contractual Clauses for international transfers. Enterprise customers may request custom terms.
Individuals may submit access, erasure, correction, restriction, portability, and opt-out requests to [email protected] or through the form at leadmagic.io/legal/privacy-request, which collects every identifier needed to action the request in one pass. We verify identity where the law permits it — never for an opt-out of sale or sharing — respond within the applicable GDPR or CCPA deadline, and coordinate with distribution partners when data was delivered through an integration.
We perform security assessments and vulnerability review appropriate to our size, risk profile, and product maturity. We do not conduct annual third-party penetration testing today. Additional documentation may be available under confidentiality upon request.
Report vulnerabilities responsibly to [email protected]. Our security.txt at /.well-known/security.txt lists current contact and policy details per RFC 9116.
Questions about security?
Security questionnaires, subprocessor documentation, and DPAs available for procurement and partner review.
Request security packContact security
Your privacy, your choice
Necessary cookies run the site. With permission, analytics improve it and ad cookies measure campaigns. Cookie Policy.