Security
Last updated: January 2026
Data Security
LeapDataHQ takes data security seriously. We implement industry-standard security measures to protect your data, including:
- Encryption in transit using TLS 1.2+ for all data transfers
- Encryption at rest for stored data
- Secure session management with HTTP-only cookies
- Password hashing using bcrypt with 12 rounds
- Stripe for payment processing (we never store full payment details)
Infrastructure
LeapDataHQ is hosted on Vercel and uses Neon for PostgreSQL database services. Both providers maintain SOC 2 compliance and industry-standard security certifications.
Data Access
Your uploaded data and enriched results are accessible only to you and your workspace members. We do not share your data with third parties except as necessary to provide the enrichment service (e.g., sending enrichment requests to configured providers).
API Key Security
If you use LeapDataHQ API keys, they are stored as hashed values. We never store plaintext API keys. You can generate, revoke, and rotate API keys from your dashboard at any time.
Reporting Vulnerabilities
If you discover a security vulnerability, please report it privately to security@leapdatahq.com. We appreciate responsible disclosure and will respond promptly.
Data Retention
We retain your data for as long as your account is active. Upon account deletion, your data is permanently removed within 30 days. Exported data that you have downloaded is no longer under our control.