LEADaEYE Security — Data Protection & Compliance Overview Skip to main content

LEADaEYE Security & Compliance

LEADaEYE Security — Data Protection & Compliance Overview

LEADaEYE's deployed security controls protect your lead data and business intelligence at every layer of the platform. Enterprise-grade security for field sales teams.

Single Sign-On & Multi-Factor Authentication

Employees log in with their company identity provider via SAML 2.0 (Okta, Azure AD, OneLogin). Multi-factor authentication adds extra verification for sensitive actions like billing changes and API key access (TOTP, step-up challenges).

Tenant Isolation

Tenant isolation is enforced through application-layer authorization and PostgreSQL Row-Level Security (RLS). Each organization's data is scoped by org context — users can only access their own organization's records. Privileged administrative paths are separately controlled from normal runtime traffic.

AI Data Privacy

Your business data is never used to train AI models. All AI API calls are governed by enterprise data processing agreements that prohibit training and retention of customer inputs.

Encryption

Data is encrypted at rest using AES-256-GCM and in transit using TLS 1.2+, with HSTS configured. Backups are AES-256-GCM encrypted with unique IVs and SHA-256 checksums.

GDPR & Data Subject Rights

LEADaEYE supports GDPR data subject rights including access (Art. 15), erasure (Art. 17), rectification (Art. 16), and portability (Art. 20). Enterprise customers can execute a Data Processing Agreement (DPA) governing controller and processor obligations.

Contact

Security inquiries and vulnerability reports: security@leadaeye.com