OUR DATA PLEDGE
We don’t sell or share your data — not to advertisers, not to brokers, not to anyone.
Findings stay in your account. We don’t monetize search history, identifiers, or report data — our only revenue is the subscription or one-time fee on your invoice. We don’t sell or share user data — not account info, not search queries, not report data — so the “sale” and “share” opt-outs that other services offer under U.S. privacy laws (CCPA/CPRA) aren’t needed here. Aggregate query telemetry stays internal and is never tied back to an individual or workspace externally. Receipts say tax included; nothing is added on top.
CERTIFICATIONS & COMPLIANCE
FCRAWe are not a consumer reporting agency. Prohibited uses gated off. →● IN PLACE DPPAPermitted-use attestation flow on workspaces with driver-license access. →● IN PLACE CCPA / CPRAStructured rights flow + 45-day response window. We do not sell or share. →● IN PLACE PCI DSSSAQ A — Stripe handles all cardholder data. No card numbers touch our servers. →● IN PLACE GLBA Safeguards RuleWritten information-security program in development. Required since June 2023.● IN PROGRESS
California data broker (SB 362)Registration under evaluation. DELETE Act central-deletion compliance committed. →● IN PROGRESS Vermont / Texas / Oregon brokersRegistrations under evaluation in each jurisdiction. →● IN PROGRESS GDPR / UK GDPRDPIA + ROPA + DPA template in development. DPO: dpo@idleakcheck.com.● IN PROGRESS
SOC 2 Type IINot started. Will begin when enterprise customer demand warrants the engagement.● NOT STARTED
ISO 27001Not started. Will begin when EU enterprise demand warrants the engagement.● NOT STARTED
TECHNICAL CONTROLS
TRANSPORT ENCRYPTIONTLS 1.2+ on every endpoint, HSTS at the edge, Cloudflare-fronted.
APPLICATION ENCRYPTIONAES-256-GCM envelope on every authenticated API call. Per-session ephemeral key, anti-replay nonce, replay window 90s.
ENCRYPTION AT RESTPostgreSQL native encryption at the hosting layer. Password hashes via bcrypt; recovery codes hashed before storage.
AUTHENTICATIONEmail + password. Optional TOTP two-factor with 10 single-use recovery codes. New-device verify-via-email gate.
DEVICE TRUST30-day fingerprint-trust after the first successful new-device login-verify. Per-account 3 active sessions cap.
ACCESS CONTROLPer-workspace feature flags (admin-managed). Per-session JWT with database-backed revocation. Owner / admin / member roles.
AUDIT LOGAppend-only activity log of every authenticated action. Admin-exportable. Retention per plan.
DATA RESIDENCYApplication and primary database hosted in OVHcloud EU regions (France / Germany). Sub-processors listed below.
SUB-PROCESSORSOVHcloud, Stripe, Cloudflare, Postmark, Sentry — full list at /legal/subprocessors with 30-day change notice. INCIDENT RESPONSE72-hour personal-data breach notification commitment per GDPR Art 33. Best-effort customer notification on confirmed incidents.
RESPONSIBLE DISCLOSURE
Found something? Email security@idleakcheck.com with reproduction steps. We treat every report seriously and reply to every one. We do not currently operate a formal bug-bounty program. Please give us a reasonable window to investigate and patch before any public disclosure — typically 90 days, sooner for low-risk issues. Full terms in our security article.
Security questions from procurement?
We can answer security questionnaires and walk through our controls on a call. Most enterprise reviews complete in 1–2 weeks.
Talk to salesNeed a Data Processing Addendum (DPA)?
Read the overview at /legal/dpa, then email legal@idleakcheck.com for the executable version.
View DPA overview