Security

Last updated: June 18, 2026

All Systems Operational

Uptime: 99.9% · Report an issue: [email protected]

1. Infrastructure Security

1.1 Hosting

iLeadX is deployed on dedicated infrastructure with strict access controls. Our servers are configured with minimal attack surface, automatic security updates, and firewall rules restricting access to necessary ports only.

1.2 Encryption

LayerStandard
Data in TransitTLS 1.3 with strong cipher suites. All API and dashboard traffic is encrypted end-to-end.
PasswordsArgon2id hashing with unique per-password salts. Passwords are never stored in plaintext.
API TokensJWT (HS256) with short expiration (8 hours) and refresh token rotation.
Payment DataCard numbers never touch our servers. All payments are tokenized by Paystack, Stripe, or NowPayments.

2. Access Control

ControlDescription
Role-Based AccessThree-tier hierarchy: User → Admin → Super Admin. Each role has strictly defined permissions.
Two-Factor AuthenticationTOTP-based 2FA (RFC 6238). Mandatory for admin accounts, optional for users.
Session ManagementPer-device session tracking with device fingerprinting. Users can view and revoke sessions remotely.
IP LoggingIP addresses logged for all sessions. Displayed as masked (e.g., 192.168.1.***) for privacy.
Rate LimitingAPI rate limits on authentication, exports, and search endpoints to prevent abuse.

3. Audit & Monitoring

CapabilityDescription
Admin Audit TrailAll administrative actions logged with timestamp, admin identity, target, old value, and new value.
Action Types TrackedUser deletion, role changes, plan changes, login events, settings changes, usage resets.
Search DiagnosticsPer-search timing breakdowns available for debugging and performance monitoring.
System HealthContinuous monitoring of API responsiveness, database health, and scraping infrastructure.

4. Compliance

StandardStatus
SOC 2 Type IIWorking toward certification. Security controls designed to meet Trust Services Criteria for Security, Availability, and Confidentiality.
GDPRCompliant. Data Processing Agreement available for Enterprise customers. EU Standard Contractual Clauses available upon request.
CCPA/CPRACompliant. We do not sell personal data. Data subject requests processed within 30 days.
SSL/TLS256-bit encryption. All connections enforce HTTPS with HSTS.

5. Vulnerability Disclosure

If you discover a security vulnerability in iLeadX, please report it to [email protected]. We request that you:

We treat all vulnerability reports with the highest priority and aim to acknowledge receipt within 24 hours.

6. Incident Response

In the event of a security incident affecting user data:

7. Contact

Security inquiries: [email protected]
Subject: "Security Inquiry"
Response time: Within 24 hours for security matters

← Back to iLeadX