Leadboard runs on enterprise-grade cloud infrastructure with automatic scaling, redundancy, and geographic distribution. Our servers are hosted in SOC 2 certified data centers with physical security controls, biometric access, and 24/7 monitoring.
We encrypt data at every layer:
We follow the principle of least privilege. Employee access to production data is strictly limited, logged, and reviewed regularly. Multi-factor authentication is required for all internal systems. Customer data is isolated per company with role-based access controls (Owner, Admin, Marketer).
Our email infrastructure includes a multi-layer protection system: global and per-company kill switches, circuit breakers, rate limiting, per-contact cooldown periods, suppression list enforcement, and anomaly detection. SPF, DKIM, and DMARC are configured for all sending domains.
We continuously monitor for security threats and anomalies. Our incident response plan includes defined severity levels, escalation procedures, and notification timelines (within 72 hours for personal data breaches as required by GDPR).
We conduct regular security assessments including automated vulnerability scanning, dependency auditing, and periodic penetration testing. Identified vulnerabilities are triaged and remediated based on severity.
If you discover a security vulnerability, please report it to security@leadboard.io. We take all reports seriously and will respond within 48 hours.