Our security architecture, compliance posture, data handling practices, and privacy commitments, transparently published in one place. No request required.
Cybercriminals use AI to enumerate targets, personalize phishing, and index breach data within hours of a leak. LeakTrace's trust posture is designed for that pace: encryption at rest, a confidentiality agreement in both directions, a consent check before any scan of a named person, and a logged retention policy. Continuous coverage without ever storing what shouldn't be stored.
Our compliance posture aligns to PIPEDA, SEC Reg S-P, GLBA, FINRA, FTC Safeguards Rule, NIST CSF 2.0, and additional jurisdictional frameworks applicable to individual and business clients worldwide. Encryption standards and data residency requirements maintained across every engagement.
Federal Trade Commission Act, the primary US federal law governing data security and privacy practices. All LeakTrace data processing is fully compliant with FTC guidelines and enforcement standards.
California Consumer Privacy Act and California Privacy Rights Act compliance for all US-resident users. Includes full right-to-deletion, opt-out of data sale, and disclosure rights.
All data at rest is encrypted using AES-256. All data in transit is secured using TLS 1.3. Encryption keys are managed using industry-standard key management systems with no shared keys.
All data processing, storage, and compute occurs within Canada and the United States. No data is transferred to, processed in, or accessible from outside North America.
Personal identifiable information provided during a scan is not retained after report delivery. No user profiles. No persistent databases of scan subjects. We find your exposure, we do not become part of it.
We are not SOC 2 certified and no audit is underway. It is on the roadmap rather than in progress, and we would rather say so than imply otherwise. What is in place today is documented above and below: encryption at rest and in transit, role-based access, and a defined retention policy.
The technical and operational controls that govern how LeakTrace systems are built, operated, and monitored.
All internal system access requires multi-factor authentication. Role-based access controls restrict data access to the minimum required for each function. No standing administrative privileges, privileged access is just-in-time and fully logged.
Production infrastructure is isolated from development and staging environments. All configuration changes are code-reviewed and deployed through automated pipelines. Unauthorized changes to production are automatically detected and escalated.
AES-256 encryption at rest for all stored data. TLS 1.3 for all data in transit. Encryption keys are held separately from encrypted data and are not stored in the application repository. No plaintext storage of sensitive identifiers.
Application errors and exceptions are captured by a third-party monitoring service and alert us directly. Repeated failed logins are rate limited and the originating address is blocked automatically.
All code changes undergo peer review before deployment. A pre-commit check blocks template and stylesheet defects that have previously reached production. Security reviews are required for all feature changes that touch data handling.
We have not commissioned an external penetration test of our own production environment, and no engagement is underway. What is in place is documented above: an isolated production environment, encryption at rest and in transit, role-based access, and a defined retention policy. Vulnerability reports about our own systems are welcome at [email protected] and are acknowledged within one business day.
A precise statement of what data is collected, how long it is retained, and what happens to it after your scan or assessment is complete.
Email addresses and domain inputs used to run a scan are retained, with the originating IP address, so we can measure demand and prevent abuse. They are purged on the schedule set out in our Privacy Policy. We do not sell them, and individual scanners who do not purchase are never sent marketing email.
Delivered reports are accessible via the dashboard for the duration of an active subscription. On cancellation, report data is deleted within 30 days. You may request immediate deletion at any time.
Name, email, and payment information required to operate your account. Payment data is processed by Stripe and never stored on LeakTrace systems. Account data is deleted on cancellation within 30 days.
Anonymised usage data is collected to improve the platform. No user-identifiable information is included in analytics. Data is never sold or shared with third parties for advertising purposes.
How to report a vulnerability, request compliance documentation, or exercise your privacy rights.
If you have identified a potential security vulnerability in any LeakTrace system, please contact our security team directly. We commit to acknowledging your report within 24 hours and providing a remediation timeline within 5 business days. We do not pursue legal action against good-faith researchers.
[email protected]Clients may request our data processing agreement, our retention and deletion policy, or written answers to a security questionnaire. We do not hold a third-party audit report and do not claim one. Documentation is shared under a confidentiality agreement. Contact us to initiate a request.
Request DocumentationYou may request access to, correction of, or deletion of any personal information LeakTrace holds about you. Requests are processed within 30 days. To opt out of communications, email us or reply STOP to any SMS.
[email protected]Our public Security Standards page documents the full set of controls, policies, and procedures that govern the LeakTrace platform, written for technical and compliance audiences.
Read Security StandardsMaterial changes to our security posture, compliance status, or privacy practices, documented as they occur.
Upgraded all production endpoints to enforce TLS 1.3. TLS 1.0 and 1.1 deprecated and blocked. All traffic now uses HSTS with a 1-year max-age.
CompletedScan subject data (email addresses and domain inputs) is now automatically purged from all systems within 24 hours of report delivery. Retention policy documented and auditable.
CompletedFull legal review of data processing practices against CCPA and CPRA requirements completed. Privacy policy updated to reflect new consumer rights disclosures. Data deletion workflow implemented.
Completed