Security and messaging compliance are built into how LeadsCoda works, not bolted on. Here's exactly where we stand, with nothing overstated.
All traffic between you, your leads, and LeadsCoda is encrypted in transit.
Databases are encrypted at rest, and API keys and tokens get an extra layer of application-level encryption.
Per-lead SMS consent records, STOP opt-outs honored automatically, quiet hours enforced.
Unsubscribe links are enforced on every marketing email, and opt-outs stop sequences instantly.
Data export and deletion on request, a signable DPA, documented subprocessors, and consent on every contact.
We never sell personal information. Know, access, and delete rights honored.
Card details go straight to Stripe and never touch LeadsCoda servers.
Workspace data is isolated per customer, and sessions use signed, httpOnly cookies.
LeadsCoda runs on providers that carry independently audited certifications like SOC 2 Type II, ISO 27001, and PCI DSS. To be precise: these are our providers' certifications, not LeadsCoda's own. Your data is handled on top of infrastructure that meets those bars, and we're candid about the difference.
SOC 2 Type II · ISO 27001
SOC 2 Type II
PCI DSS Level 1 · SOC 2 Type II
SOC 2 Type II · ISO 27001
SOC 2 Type II
Every lead carries its own email and SMS consent record with a timestamp. Sequences check consent before every single send. A STOP reply or an unsubscribe click halts messaging to that lead immediately, across every sequence, and the product won't let an SMS-first template ship without opt-out language. Imported lists carry per-row consent so old spreadsheets can't silently become spam.
You own your workspace data and can export it or ask for deletion at any time. We never sell personal information and never use your leads to advertise or to train anything. When you connect an integration, its credentials are encrypted with application-level encryption before they're stored, and they're only decrypted at the moment of use.
SOC 2 Type II certification is planned as we grow. We only display badges we've actually earned, so you'll see it here the day the audit completes and not a day before. In the meantime our practices above are written to align with SOC 2 trust principles from day one.
LeadsCoda runs on a small, deliberate set of infrastructure providers. Each one processes data only for the purpose listed.
| Provider | Purpose | Region |
|---|---|---|
| Vercel | Application hosting | United States |
| Neon | Database (PostgreSQL) | United States |
| Resend | Email delivery | United States |
| Twilio | SMS delivery | United States |
| Stripe | Payments and billing | United States |
| Meta Platforms | Lead ads sync (only when you connect it) | United States |
We welcome responsible disclosure. Email security@leadscoda.com and we'll respond within two business days.
See also our Privacy Policy, Terms of Service, and Data Processing Agreement.