← Back to Lead Validator Pro

Security Overview

Last updated: May 20, 2026   GLBA Compliant SOC 2 Readiness 2026

Contents

  1. Data Storage
  2. Encryption
  3. Access Control
  4. Backups
  5. Tenant Isolation
  6. Network Security
  7. Compliance Status
  8. Contact

1. Data Storage

Your data is stored in managed PostgreSQL hosted by Render (US-based infrastructure) with encryption at rest enabled at the storage layer. All organizations share a single logical database with row-level security (RLS) enforcing strict tenant isolation — your data is never mixed with other customers.

2. Encryption

3. Access Control

4. Backups

5. Tenant Isolation

6. Network Security

7. Compliance Status

StandardStatusDetails
GLBA Safeguards RuleImplementedMFA enforced, access controls implemented, WISP maintained internally
CCPA / CPRAImplementedSelf-serve erasure and portability endpoints + GPC honored; DNS opt-out per Privacy § 7.1
TDPSA (Texas)ImplementedRight to access, correct, delete, port, opt-out per Privacy § 8
GDPR / UK GDPRAvailable for enterpriseSCC Module 2 + UK IDTA incorporated in DPA § 12
SOC 2 Type IIReadiness in progress (target 2026)Internal readiness pack maintained; SIG-Lite / CAIQ-Lite responses available on request to security@leadvalidatorpro.com
WISPMaintained internallyWritten Information Security Program reviewed annually
TCPA AllocationDocumentedCustomer/Processor allocation per Terms § 5

Infrastructure sub-processors (Render, Cloudflare, WorkOS, Stripe, Resend, Sentry, Anthropic, Google) hold current SOC 2 Type II or equivalent (ISO 27001, FedRAMP, PCI DSS) attestations. Certification status per sub-processor is disclosed at /subprocessors.

8. Contact

For security questions or to report a vulnerability: support@leadvalidatorpro.com