Trust Center
What we do to protect your business — stated plainly, without inflated claims.
Workspace isolation
Every customer gets a separate workspace. Our APIs verify workspace ownership on every request — one business can never see another business’s leads, messages, or data.
Encrypted connections
All traffic between your browser and LeadPilot AI travels over HTTPS. Data is encrypted in transit.
Secure authentication
Sign-in uses industry-standard session authentication. Passwords are never stored in plain text, and you can sign out of all devices at any time.
Role-based access
Team members get only the permissions their role allows — owner, admin, member, or read-only viewer.
Secrets stay server-side
API keys, tokens, and integration credentials are stored server-side and are never sent to the browser or exposed through customer APIs.
Audit logging
Administrative actions on your account are recorded with who did what and when, so there is always a trail.
What we do not claim
- We do not claim third-party security certifications (such as ISO 27001 or SOC 2). If we earn them in the future, we will list them here with evidence.
- We do not claim your data is immune to all attacks. We apply the practices above and keep improving them.
- AI replies are generated from your approved Business Brain facts. The AI is instructed never to invent pricing or policies — but you should still review anything unusual, which is why approvals exist.
Your data, your control
You can request an export or deletion of your data at any time from Settings, or by contacting support. Suspending an account never deletes data — renewing restores everything exactly as it was.
Read the Privacy PolicyReport a security issue
Found something that looks wrong? Tell us right away and we will investigate. We take every report seriously.
Contact support from your account
