Trust Center
Use this page for a concise view of how LeadRecoverly protects CRM access and customer data.
Current controls
- OAuth-based HubSpot access with least-privilege scopes
- Read-only scanning by default
- Paid Edit Mode must be enabled before writes
- Preview, explicit approval, typed confirmation and audit logs for bulk actions
- Server-side tier enforcement
- Encrypted session cookies and server-only secrets
- Stripe signature verification and idempotency protections
- Row-level security and browser-role revocation in the supplied Supabase schema
- Operational monitoring, reconciliation and retention controls
Data practices
LeadRecoverly stores only the data needed to provide reports, history, approved actions, account operations and support. Customers can request deletion through the published data-deletion process.
Independent assurance
LeadRecoverly does not currently claim SOC 2 certification or an independent penetration-test attestation. Those items require qualified third-party assessment and cannot be created by application code.
Responsible disclosure
Report suspected vulnerabilities to support@leadrecoverly.com. Do not access, alter or retain customer data beyond what is necessary to demonstrate the issue.
Documents
Security · Privacy · DPA · Terms · security.txt