Skip to content
idleakcheck

How we protect what you trust us with.

We process sensitive identity data for a living. The controls below describe how we actually handle it — what’s shipped, what’s in progress, and what we haven’t done yet. We are deliberate about the difference.

OUR DATA PLEDGE

We don’t sell or share your data — not to advertisers, not to brokers, not to anyone.

Findings stay in your account. We don’t monetize search history, identifiers, or report data — our only revenue is the subscription or one-time fee on your invoice. We don’t sell or share user data — not account info, not search queries, not report data — so the “sale” and “share” opt-outs that other services offer under U.S. privacy laws (CCPA/CPRA) aren’t needed here. Aggregate query telemetry stays internal and is never tied back to an individual or workspace externally. Receipts say tax included; nothing is added on top.

Read the policy

CERTIFICATIONS & COMPLIANCE

FCRAWe are not a consumer reporting agency. Prohibited uses gated off. IN PLACE
DPPAPermitted-use attestation flow on workspaces with driver-license access. IN PLACE
CCPA / CPRAStructured rights flow + 45-day response window. We do not sell or share. IN PLACE
PCI DSSSAQ A — Stripe handles all cardholder data. No card numbers touch our servers. IN PLACE
GLBA Safeguards RuleWritten information-security program in development. Required since June 2023.IN PROGRESS
California data broker (SB 362)Registration under evaluation. DELETE Act central-deletion compliance committed. IN PROGRESS
Vermont / Texas / Oregon brokersRegistrations under evaluation in each jurisdiction. IN PROGRESS
GDPR / UK GDPRDPIA + ROPA + DPA template in development. DPO: dpo@idleakcheck.com.IN PROGRESS
SOC 2 Type IINot started. Will begin when enterprise customer demand warrants the engagement.NOT STARTED
ISO 27001Not started. Will begin when EU enterprise demand warrants the engagement.NOT STARTED

TECHNICAL CONTROLS

TRANSPORT ENCRYPTIONTLS 1.2+ on every endpoint, HSTS at the edge, Cloudflare-fronted.
APPLICATION ENCRYPTIONAES-256-GCM envelope on every authenticated API call. Per-session ephemeral key, anti-replay nonce, replay window 90s.
ENCRYPTION AT RESTPostgreSQL native encryption at the hosting layer. Password hashes via bcrypt; recovery codes hashed before storage.
AUTHENTICATIONEmail + password. Optional TOTP two-factor with 10 single-use recovery codes. New-device verify-via-email gate.
DEVICE TRUST30-day fingerprint-trust after the first successful new-device login-verify. Per-account 3 active sessions cap.
ACCESS CONTROLPer-workspace feature flags (admin-managed). Per-session JWT with database-backed revocation. Owner / admin / member roles.
AUDIT LOGAppend-only activity log of every authenticated action. Admin-exportable. Retention per plan.
DATA RESIDENCYApplication and primary database hosted in OVHcloud EU regions (France / Germany). Sub-processors listed below.
SUB-PROCESSORSOVHcloud, Stripe, Cloudflare, Postmark, Sentry — full list at /legal/subprocessors with 30-day change notice.
INCIDENT RESPONSE72-hour personal-data breach notification commitment per GDPR Art 33. Best-effort customer notification on confirmed incidents.
RESPONSIBLE DISCLOSURE

Found something? Email security@idleakcheck.com with reproduction steps. We treat every report seriously and reply to every one. We do not currently operate a formal bug-bounty program. Please give us a reasonable window to investigate and patch before any public disclosure — typically 90 days, sooner for low-risk issues. Full terms in our security article.

Security questions from procurement?

We can answer security questionnaires and walk through our controls on a call. Most enterprise reviews complete in 1–2 weeks.

Talk to sales
Need a Data Processing Addendum (DPA)?

Read the overview at /legal/dpa, then email legal@idleakcheck.com for the executable version.

View DPA overview