LeadsCoda
Trust & Security

Your leads are your business. We treat them that way.

Security and messaging compliance are built into how LeadsCoda works, not bolted on. Here's exactly where we stand, with nothing overstated.

TLS 1.2+ everywhere

All traffic between you, your leads, and LeadsCoda is encrypted in transit.

Encrypted at rest

Databases are encrypted at rest, and API keys and tokens get an extra layer of application-level encryption.

TCPA-aware texting

Per-lead SMS consent records, STOP opt-outs honored automatically, quiet hours enforced.

CAN-SPAM compliant email

Unsubscribe links are enforced on every marketing email, and opt-outs stop sequences instantly.

GDPR compliant

Data export and deletion on request, a signable DPA, documented subprocessors, and consent on every contact.

CCPA compliant

We never sell personal information. Know, access, and delete rights honored.

PCI DSS payments via Stripe

Card details go straight to Stripe and never touch LeadsCoda servers.

Least-privilege access

Workspace data is isolated per customer, and sessions use signed, httpOnly cookies.

Built on certified infrastructure

LeadsCoda runs on providers that carry independently audited certifications like SOC 2 Type II, ISO 27001, and PCI DSS. To be precise: these are our providers' certifications, not LeadsCoda's own. Your data is handled on top of infrastructure that meets those bars, and we're candid about the difference.

VercelHosting & edge network

SOC 2 Type II · ISO 27001

NeonManaged Postgres

SOC 2 Type II

StripePayments

PCI DSS Level 1 · SOC 2 Type II

TwilioSMS delivery

SOC 2 Type II · ISO 27001

ResendEmail delivery

SOC 2 Type II

Consent is enforced by the product

Every lead carries its own email and SMS consent record with a timestamp. Sequences check consent before every single send. A STOP reply or an unsubscribe click halts messaging to that lead immediately, across every sequence, and the product won't let an SMS-first template ship without opt-out language. Imported lists carry per-row consent so old spreadsheets can't silently become spam.

Your data stays yours

You own your workspace data and can export it or ask for deletion at any time. We never sell personal information and never use your leads to advertise or to train anything. When you connect an integration, its credentials are encrypted with application-level encryption before they're stored, and they're only decrypted at the moment of use.

On our roadmap, stated honestly

SOC 2 Type II certification is planned as we grow. We only display badges we've actually earned, so you'll see it here the day the audit completes and not a day before. In the meantime our practices above are written to align with SOC 2 trust principles from day one.

Subprocessors

LeadsCoda runs on a small, deliberate set of infrastructure providers. Each one processes data only for the purpose listed.

ProviderPurposeRegion
VercelApplication hostingUnited States
NeonDatabase (PostgreSQL)United States
ResendEmail deliveryUnited States
TwilioSMS deliveryUnited States
StripePayments and billingUnited States
Meta PlatformsLead ads sync (only when you connect it)United States

Found something?

We welcome responsible disclosure. Email security@leadscoda.com and we'll respond within two business days.

See also our Privacy Policy, Terms of Service, and Data Processing Agreement.