Security
Security built for your revenue data
We hold your ad spend, lead records, pipeline and revenue. Encryption throughout the stack, strict access controls, EU hosting, privacy by design.
- AES-256 at rest
- TLS in transit
- EU hosting (Frankfurt)
- Two-factor auth
- Signed webhooks
- GDPR and DPA
Rated by the teams who trust us with their data
Trusted by 100+ lead generation businesses, agencies and freelancers
Defence in depth
Protection at every layer of the stack
Security is not one control, it is many working together. Here is how we protect access, data, infrastructure and operations.
Access and identity
- Two-factor authentication (TOTP)
- Enforced password complexity
- bcrypt password hashing, 12 rounds
- Token and Redis backed sessions
Encryption
- AES-256 at rest for sensitive data
- TLS enforced in transit
- Encrypted OAuth and 2FA secrets
- Encrypted recovery codes
Infrastructure
- Hosted in Frankfurt, Germany (EU)
- Kubernetes orchestrated services
- Least privilege across services
- Encrypted credentials at rest
Monitoring
- Exception and performance monitoring
- Centralised log aggregation
- Real-time alerting to the team
- Signed, verified inbound webhooks
Access and authentication
Only the right people get in
Every account is protected by modern authentication, and access to production systems follows the principle of least privilege.
Two-factor authentication
TOTP based 2FA, for example Google Authenticator, with encrypted recovery codes so a lost device never means a lost account.
Passwords
Enforced complexity: a minimum length with upper and lower case, numbers and symbols. Hashed with bcrypt at 12 rounds, never stored in plain text.
Sessions and tokens
API access uses Laravel Sanctum tokens, with sessions backed by Redis for fast, controlled invalidation.
Integrations
Connected platforms authorise through OAuth 2.0, so we never handle the credentials of your ad and marketing accounts.
Encryption
Encrypted in transit and at rest
Data is protected on the wire and in the database, with the most sensitive fields encrypted individually.
In transit
All traffic is served over HTTPS and TLS in production. Nothing sensitive travels unencrypted.
At rest
AES-256-CBC encryption for OAuth tokens, two-factor secrets and personal data held in the database.
Secrets management
Application secrets are managed through environment configuration. Integration tokens and webhook secrets are encrypted in the database.
Credentials
Credentials are never stored in plain text and are held with least privilege scope across services.
Infrastructure and data residency
Hosted in the EU, in Frankfurt
We chose EU based infrastructure so European teams keep their core data in the European Union by default.
Location
Production infrastructure is located in Frankfurt, Germany, inside the European Union.
Platform
Services run on Kubernetes: MySQL, Redis and Soketi for realtime, orchestrated as isolated, least privilege services.
File storage
Uploaded files are stored on Amazon S3.
Sub-processors
We keep a current, public list of every sub-processor with access to data on our GDPR page.
Integrations and webhooks
Verified data in, secrets out of reach
LeadJourney connects to your ad platforms and tools. Those connections are authenticated, and everything flowing into the platform is verified.
Signed webhooks
Every inbound webhook is verified with an HMAC-SHA256 or Ed25519 signature before it is accepted, so forged events are rejected.
Encrypted tokens
Integration tokens and webhook secrets are encrypted in the database, separate from the rest of your data.
Logging and monitoring
Watched around the clock
We watch for errors, performance regressions and anomalies, with alerts routed to the team in real time.
Exceptions and performance
Application errors and performance are monitored with Laravel Nightwatch.
Centralised logs
Logs are aggregated centrally in LogDNA for search and investigation.
Alerting
Alerts are pushed to Slack so issues reach the team quickly.
Privacy and compliance
Privacy is built in, not bolted on
LeadJourney is built for European marketing and revenue teams, so data protection is part of the foundation.
GDPR
EU data residency, lawful basis tracking, sub-processor transparency and full data subject rights. See our GDPR and data protection page.
Data Processing Agreement
An Art. 28 GDPR compliant DPA is available on request to customers who process personal data through LeadJourney.
Data Protection Officer
We have an appointed DPO, reachable at [email protected].
First-party tracking
LeadJourney is built on first-party, server-side tracking, which cuts the reliance on third-party cookies.
Responsible disclosure
Found something? We want to hear from you
If you believe you have found a security vulnerability, please tell us before disclosing it publicly. Email the details and the steps to reproduce, and we will come back to you quickly. We will not pursue legal action against good faith researchers who report responsibly.
We aim to respond quickly and to keep you updated until the report is closed.
FAQ
The questions security teams ask us
Everything a vendor review usually asks, answered here so you do not have to send the questionnaire first.
Where is my data stored?
All production infrastructure runs in Frankfurt, Germany, inside the European Union. Application, database (MySQL), cache (Redis) and realtime (Soketi) services run on Kubernetes there, and file storage is on Amazon S3. European customers keep their core data in the EU by default.
Is my data encrypted?
Yes. All traffic is served over HTTPS and TLS in production. Sensitive data, including OAuth tokens, two-factor secrets and personal data, is encrypted at rest with AES-256.
Do you support two-factor authentication?
Yes. LeadJourney supports TOTP based two-factor authentication, for example Google Authenticator, with encrypted recovery codes.
How are passwords stored?
Passwords must meet complexity rules (minimum length, upper and lower case, numbers and symbols) and are hashed with bcrypt at 12 rounds. We never store passwords in plain text.
Do you support SAML single sign-on?
Not yet. We use OAuth 2.0 for connected integrations, but SAML single sign-on for user login is not available. If your team needs it, contact us and tell us about your requirements.
How do you secure integrations and webhooks?
Integration tokens and webhook secrets are encrypted in the database, and secrets are managed through environment configuration. Every inbound webhook is verified with an HMAC-SHA256 or Ed25519 signature before it is processed.
Do you offer a Data Processing Agreement?
Yes. If you process personal data through LeadJourney, we make a DPA available on request that meets the requirements of Art. 28 GDPR. Email [email protected] and we will send it.
Are you GDPR compliant?
Yes. We host in the EU, publish a list of sub-processors, support data subject rights and have an appointed Data Protection Officer. The full detail is on our GDPR and data protection page.
Passing a security review
We will help your team through procurement
Ask for the security overview, the DPA and our technical and organisational measures in one email, and we will send the set.



