Security
Last updated: June 13, 2026
We build LeadAgent to keep your data — and your clients' data — safe. This page summarizes the technical and organizational measures we use to protect personal information. It complements our Privacy Policy.
1. Data Residency
All customer data is hosted in Canada, in Amazon Web Services' Canada (Central) region (ca-central-1). Your data does not leave Canadian infrastructure for storage. A small number of sub-processors named in our Privacy Policy (for example Stripe for payments) may process limited data elsewhere to perform their function.
2. Encryption
Data is encrypted in transit using TLS 1.2 or higher, and at rest using AES-256. Third-party access tokens for your connected integrations are stored encrypted in AWS Secrets Manager, separate from your application data.
3. Access Controls
Access to production systems is restricted on a least-privilege basis. Each subscriber's data is isolated to their own account, and application requests are authenticated and authorized so that one account cannot read or modify another's data.
4. Auditing and Monitoring
Security-relevant events — including authentication, password changes, and administrative actions — are logged and retained for review. We monitor our infrastructure for availability and anomalous activity.
5. Backups and Availability
We operate on redundant cloud infrastructure with automated backups. Backups are retained on a rolling basis and age out over time, so data removed during a deletion request is not retained indefinitely in backups.
6. Data Deletion
You can request deletion of your account and personal data from within the app (Settings → Privacy & Data) or by contacting our Privacy Officer. Deletion is processed on a 30-day grace period, after which personal data is permanently erased, except for records we are required to retain by law (such as payment and tax records). See the Privacy Policy for details.
7. Incident Response
We maintain a documented process to identify, contain, assess, and remediate security incidents. Where a breach of security safeguards creates a real risk of significant harm, we notify the Office of the Privacy Commissioner of Canada and affected individuals as required by PIPEDA.
8. Reporting a Vulnerability
If you believe you have found a security vulnerability, please report it to security@softurns.ai. We appreciate responsible disclosure and will investigate every legitimate report.
Softurns Technologies
Security: security@softurns.ai
Privacy Officer: Shibu Cherian (privacy@softurns.com)
Address: 80 Atlantic Avenue, 4th Floor, Ontario M6K 1X9, Canada