Trust & security

Security & sub-processors

The controls we operate today, the providers that touch data, and how to reach us about a security matter. Described as they are, not as certifications.

Operating policy · v1Last updated 27 September 2026·Questions: dpo@leadradar.example

Architecture controls

Operations

Sub-processors

ProviderPurposeLocationData
Hetzner Online GmbHHosting (Falkenstein, Germany)EUApplication, database, worker
SupabaseManaged PostgreSQL and authEU regionTenants, evidence, audit
FirecrawlFetching public pagesSee provider terms; only public URLs are sentPublic source text
OpenAI (API)Extraction, explanations, draftsPer contract; EU-resident model option availablePublic source text and approved facts; no CRM or accounting data
HubSpotCustomer's own CRMCustomer's account and regionApproved records only

Certifications

ISO/IEC 27001 certification is in progress (see programme status). We do not claim SOC 2, ISO or "GDPR-certified" as achieved. A summary of our controls is available on request; an audit report follows the first external audit.

Contact

security@leadradar.example · vulnerability reports: see Responsible disclosure.

Items highlighted like this are filled in per customer or before launch. We describe controls we operate; we do not present GDPR compliance, AI Act conformity or ISO certification as achieved results until verified.