Security & sub-processors
The controls we operate today, the providers that touch data, and how to reach us about a security matter. Described as they are, not as certifications.
Operating policy · v1Last updated 27 September 2026·Questions: dpo@leadradar.example
Architecture controls
- Tenant isolation enforced in the database with row-level security and tested with two separate identities; checked in UI, API, worker and every evidence read.
- Roles: admin, sales, reviewer, with explicit rights; purpose-based access planned.
- Audit log of actor, object, version, change, reason, approval and result for every decision and external write.
- Idempotent outbox for CRM writes; no duplicate records, no write without approval.
- Safe ingestion: URL and destination checks, SSRF protection including redirects, size and time limits, controlled parsing; documents get no tool permissions.
- Secrets in a vault, OAuth tokens rotated every 30–90 days, one-click "revoke all tokens".
- Encryption in transit (TLS 1.2+) and at rest; backups encrypted; deletion propagates to indexes, caches and derived results.
Operations
- Cost ceilings per job, tenant and day; circuit breakers on external APIs; Source Health page with last success and data age.
- Monthly audit-log review; quarterly scoring-bias audit; monthly opt-out test.
- Incident response: contain, revoke, notify affected customers, report to the authority within 72 hours where required, post-mortem.
Sub-processors
| Provider | Purpose | Location | Data |
|---|---|---|---|
| Hetzner Online GmbH | Hosting (Falkenstein, Germany) | EU | Application, database, worker |
| Supabase | Managed PostgreSQL and auth | EU region | Tenants, evidence, audit |
| Firecrawl | Fetching public pages | See provider terms; only public URLs are sent | Public source text |
| OpenAI (API) | Extraction, explanations, drafts | Per contract; EU-resident model option available | Public source text and approved facts; no CRM or accounting data |
| HubSpot | Customer's own CRM | Customer's account and region | Approved records only |
Certifications
ISO/IEC 27001 certification is in progress (see programme status). We do not claim SOC 2, ISO or "GDPR-certified" as achieved. A summary of our controls is available on request; an audit report follows the first external audit.
Contact
security@leadradar.example · vulnerability reports: see Responsible disclosure.
Items highlighted like this are filled in per customer or before launch. We describe controls we operate; we do not present GDPR compliance, AI Act conformity or ISO certification as achieved results until verified.