Snapshot 44775
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Skip to main content New Unlimited Search is live — zero-credit People, Company & Jobs Search at 5–10 RPSUnlimited Search is live Try Unlimited Security & Trust Enterprise security for your enrichment layer LeadMagic maintains a written information security program with encryption in transit and at rest, enforced MFA on workforce and critical systems, least-privilege access, centralized logging, vendor governance, and a published Privacy Policy and DPA. We honor GDPR and CCPA/CPRA data subject requests. Request security packView DPA Security program Built for teams with real compliance requirements A defense-in-depth program for B2B data infrastructure — encryption, identity controls, monitored production, vendor governance, and published privacy policies. Defense in depth Layered administrative, technical, and operational controls across workforce identity, production infrastructure, APIs, and vendor integrations. Encryption by default TLS 1.3 for data in transit and AES-256 for data at rest across supported cloud services. Secrets managed through dedicated vaults — never committed to source control. Identity & MFA Google Workspace SSO with enforced 2-Step Verification for workforce access. MFA required on critical SaaS and production dashboards. Least privilege & access reviews Role-based access with documented joiner, mover, and leaver procedures and periodic access reviews for production systems. Monitoring & logging Centralized telemetry, error tracking, and audit logging to support security investigation and operational response. Vendor & subprocessor governance Subprocessor tracking, vendor security reviews, and DPAs with infrastructure providers that handle customer or enrichment data. Control framework Four pillars of our security posture Documented policies, operational practices, and controls for teams that need clear answers during procurement and partner review. Access & identity Google Workspace as workforce IdP with enforced MFA Scoped API keys and role-based permissions for customers Production access limited to authorized engineering and operations personnel Joiner / mover / leaver checklists with same-day deprovisioning Data protection TLS 1.3 in transit; AES-256 at rest where supported by underlying services Secrets managed via Doppler and 1Password — not stored in application code Data minimization and retention limits aligned to service delivery Customer DPAs with Standard Contractual Clauses for international transfers Secure operations Production hosted on enterprise cloud infrastructure (Cloudflare, Vercel, GCP-class providers) Change management through reviewed pull requests and controlled deployments Vulnerability and dependency review as part of our secure development lifecycle Incident response procedures with partner notification within contractual timelines Privacy & compliance Published Privacy Policy and DPA; GDPR and CCPA/CPRA data subject requests honored Documented DSAR intake via [email protected] and /legal/privacy-request Written information security program with administrative and technical safeguards Responsible disclosure via [email protected] and /.well-known/security.txt Privacy Privacy programs & security posture What we publish today — no inflated certification claims. Security programDocumented administrative & technical controls Privacy requestsGDPR & CCPA/CPRA rights honored Privacy PolicyPublished data practices DPA availableStandard + enterprise terms Need a security questionnaire, subprocessor list, or custom DPA? Request documentation or email [email protected]. Responsible disclosure: report vulnerabilities to [email protected]. See security.txt for RFC 9116 contact details. FAQ Security FAQ No. LeadMagic does not hold SOC 2, SOC 2 Type II, ISO 27001, or other third-party security certifications. We maintain a written information security program with encryption, access controls, vendor review, logging, and privacy processes appropriate to our services. A DPA is available for customers who need contractual assurances. Data is encrypted in transit using TLS 1.3. Data at rest is encrypted using AES-256 across supported cloud infrastructure providers. API credentials and internal secrets are managed through dedicated secrets management — not stored in repositories or application logs. LeadMagic primarily uses cloud infrastructure in the United States. Safeguards include encryption in transit and at rest, access controls, and vendor DPAs. Custom data residency commitments require a separate written agreement. Yes. We provide a Data Processing Agreement for customers and partners, including Standard Contractual Clauses for international transfers. Enterprise customers may request custom terms. Individuals may submit access, erasure, correction, restriction, portability, and opt-out requests to [email protected] or through the form at leadmagic.io/legal/privacy-request, which collects every identifier needed to action the request in one pass. We verify identity where the law permits it — never for an opt-out of sale or sharing — respond within the applicable GDPR or CCPA deadline, and coordinate with distribution partners when data was delivered through an integration. We perform security assessments and vulnerability review appropriate to our size, risk profile, and product maturity. We do not conduct annual third-party penetration testing today. Additional documentation may be available under confidentiality upon request. Report vulnerabilities responsibly to [email protected]. Our security.txt at /.well-known/security.txt lists current contact and policy details per RFC 9116. Questions about security? Security questionnaires, subprocessor documentation, and DPAs available for procurement and partner review. Request security packContact security Your privacy, your choice Necessary cookies run the site. With permission, analytics improve it and ad cookies measure campaigns. Cookie Policy.